HONG KONG · EAST ↔ WEST
info@lockhartyip.comResponse within 4 hours (UTC+8)
Discuss your matter
Home/Insights/Disputes & Arbitration
Sanctions & AML

Reading the risk in a compliance review before contracting with the UAE entity

A compliance review before contracting with the UAE entity. Hong Kong as the neutral forum and hub. Seen from the Hong Kong desk. Write to info@lockhartyip.com.

A mid-market Asian group has identified a UAE-incorporated counterparty. The commercial terms are agreed. The question that lands on the desk of the general counsel is not whether the deal makes sense – it does – but whether the entity on the other side of the contract can be documented, banked and paid without triggering a compliance failure downstream. That is the question a structured pre-contract compliance review is designed to answer.

A compliance review before contracting with a UAE entity requires a systematic examination of four interlocking risk layers: sanctions exposure under the applicable regimes, anti-money laundering source-of-funds verification, ownership and control mapping, and banking-channel viability for the payment flows the contract will generate. The governing instruments include the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Hong Kong's primary AML statute), the United Nations Sanctions Ordinance (which implements UN Security Council measures in Hong Kong), and the UAE's own AML and sanctions framework administered through the UAE Central Bank and the Executive Office for Control and Non-Proliferation. Where the contract routes payment through a Hong Kong correspondent or clearing bank, both systems are engaged simultaneously.

This analysis examines what the review actually covers, where the cross-border interface between Hong Kong and the UAE creates friction, and where the residual risk sits after the review is complete. The argument runs across four sections: the commercial and regulatory stakes; the governing instruments and how they meet; the comparative read across the two jurisdictions; and our assessment of where the exposure concentrates in practice.

What is actually at stake when the counterparty is UAE-incorporated?

The UAE sits at an unusual intersection for Asian groups: it is simultaneously one of the most commercially active cross-border hubs connecting Asia, the Gulf, and Africa, and a jurisdiction that has spent the last several years under elevated scrutiny from international standard-setters. The Financial Action Task Force (FATF, the intergovernmental body that sets global AML and counter-terrorism-financing standards) placed the UAE on its enhanced monitoring list – commonly called the grey list – in 2022. The UAE was removed from that list in February 2024, following reforms to its legal and supervisory infrastructure. That removal is material. It does not, however, eliminate the due-diligence obligations that arise when a Hong Kong entity contracts with a UAE counterparty.

Why not? Because the compliance architecture is not driven solely by FATF status. It is driven by the obligations that apply to the Hong Kong entity under Hong Kong law, and by the risk appetite of the banks and payment infrastructure that will actually move the money. Those two factors operate independently of whether the UAE is on a grey list at any given moment.

The commercial stakes are tangible. Banking access – specifically, the willingness of a correspondent bank to process payments to or from the UAE counterparty – is the single most operationally sensitive output of the compliance review. A contract that cannot be paid through the available banking channels is commercially valueless, regardless of its legal enforceability. In our cross-border practice, we see this issue arise repeatedly: a contract is signed, the first payment is due, and the bank raises an enhanced-due-diligence request that neither party anticipated. The resulting delay costs money. In some cases, it costs the relationship.

The review exists to prevent that outcome. It maps the risk before the contract is signed, not after the payment is blocked.

Which instruments govern the review, and how do they interact?

Three bodies of law bear directly on a Hong Kong party contracting with a UAE entity. Each operates on a different vector, but all three converge on the same transaction.

The first is the Anti-Money Laundering and Counter-Terrorist Financing Ordinance. This is Hong Kong's primary AML statute. It applies to designated non-financial businesses and professions (DNFBPs, a defined category under the Ordinance that includes lawyers, accountants and corporate-service providers) and to financial institutions regulated by the Hong Kong Monetary Authority and the Securities and Futures Commission. The Ordinance imposes customer due diligence (CDD, the process of verifying the identity and ownership of a counterparty) and ongoing monitoring obligations. For a cross-border commercial contract with a UAE entity, the relevant party in Hong Kong – whether that is a regulated financial institution processing the payment or a DNFBP advising on the transaction – will be subject to the Ordinance's requirements.

The second instrument is the United Nations Sanctions Ordinance. Hong Kong implements United Nations Security Council sanctions. It does not give domestic legal effect to the unilateral sanctions measures of any other state. This is the formal position under Hong Kong law, and it has a direct bearing on how the UAE counterparty risk is assessed. The relevant screening obligation in Hong Kong is against the UN consolidated sanctions list and the specific designations made under Hong Kong law. Where a UAE entity or its beneficial owners appear on those lists, the transaction is prohibited. Where they do not appear on UN lists but do appear on a unilateral sanctions list issued by a third-state authority, the Hong Kong legal position is that no domestic prohibition applies – though the commercial exposure through correspondent banks remains a live risk.

The third body of law is the UAE's own regulatory regime. The UAE has enacted a comprehensive AML and sanctions framework, including a national AML law and a beneficial-ownership registration requirement for UAE entities. The UAE maintains its own sanctions framework, aligned substantially with UN obligations, administered through the Executive Office for Control and Non-Proliferation. A Hong Kong party entering a material commercial contract with a UAE entity should understand the counterparty's obligations under UAE law, because a UAE entity that is itself non-compliant with its domestic regime presents a heightened source-of-funds risk.

The cross-border interface bites hardest at the payment channel. A payment routed from Hong Kong to the UAE will pass through correspondent banking infrastructure. That infrastructure applies its own compliance screening – typically against a wider set of lists than Hong Kong law requires, including the unilateral measures of major reserve-currency jurisdictions. The compliance review must therefore address not only the legal obligations of the Hong Kong party but the practical requirements of the banking channel through which performance will occur.

The sequence above describes the standard position. Your matter turns on the documents, the jurisdictions actually engaged, and the order of the steps – which is where the route is won or lost. For a structured assessment of your cross-border compliance position before contracting with a UAE entity, write to us at info@lockhartyip.com.

How do the Hong Kong and UAE systems compare on the four risk layers?

A structured compliance review maps four distinct risk layers. The comparative read across Hong Kong and UAE law is materially different on each one.

Layer one: sanctions screening. Hong Kong law requires screening against UN-designated lists. The UAE requires the same, plus screening against its own national list. Neither jurisdiction requires screening against the unilateral measures of a third state as a matter of domestic law. In practice, the divergence emerges when a UAE entity has exposure to a counterparty that is designated under a unilateral regime but not under UN measures. The Hong Kong party faces no domestic legal prohibition. The payment bank may refuse the transaction regardless. The review must document this gap explicitly, so that the contracting parties understand the residual banking risk and can structure payment terms accordingly.

Layer two: beneficial ownership. The UAE introduced a beneficial-ownership register requirement for mainland UAE entities as part of its FATF reform programme. Obtaining a current, certified beneficial-ownership extract from the relevant UAE registry is now a standard step in the review. Hong Kong-incorporated companies are subject to the Significant Controllers Register (SCR, the Hong Kong beneficial-ownership regime under the Companies Ordinance, in force since 1 March 2018). A UAE counterparty conducting its own CDD on the Hong Kong party will expect SCR-equivalent disclosure. The review should therefore anticipate reciprocal disclosure obligations and prepare the relevant documentation in advance.

Layer three: source of funds. This is where the two systems produce the sharpest practical divergence. Hong Kong's AML regime requires that a regulated party obtain satisfactory evidence of the source of funds and source of wealth where the risk profile of the transaction or counterparty warrants it. For a UAE counterparty, the relevant questions are: what is the origin of the capital that will be used to perform the contract, and can that origin be documented through verifiable, non-opaque channels? UAE entities with complex ownership through offshore structures – for example, through BVI or Cayman holding vehicles that themselves have Middle Eastern or Central Asian owners – present a source-of-funds tracing challenge that requires additional documentation layers. In our cross-border practice, counsel on our desk regularly see transactions where the commercial substance of the UAE entity is entirely legitimate but the ownership chain has not been documented in a form that satisfies Hong Kong correspondent bank requirements. The fix is documentary, not structural – but it must be completed before the first payment instruction is issued.

Layer four: sector and activity screening. Certain sectors carry an elevated compliance burden regardless of the counterparty's identity. Real estate, precious metals, financial services and virtual assets attract enhanced scrutiny under both the Hong Kong and UAE AML frameworks. A commercial contract in one of these sectors with a UAE counterparty will require a more intensive review than a standard goods-supply arrangement. The review should identify the sector classification at the outset and calibrate the due-diligence scope accordingly.

Where does the risk concentrate in practice? Our read across recent mandates

The theoretical framework is well-understood by most sophisticated in-house counsel. The difficulty arises in execution – specifically, in the gap between what the legal obligation requires and what the banking infrastructure demands. Our desk sees this gap in three recurring patterns.

The first pattern is the timing problem. Compliance reviews are initiated too late – after the contract is substantially negotiated, after the counterparty has been publicly announced, and after senior management have made commitments. The review then operates under commercial pressure. A finding that requires additional documentation – or, more seriously, a finding that the payment channel will not clear the transaction as structured – is far more disruptive at that stage than it would have been at the initial mandate stage. The practical lesson is that the compliance review should begin when the letter of intent is being discussed, not when the execution copies are being circulated.

The second pattern is the unilateral-sanctions misread. A Hong Kong in-house team – sometimes advised by counsel from a jurisdiction where the unilateral measures of a particular state are mandatory – applies that state's sanctions list as though it were binding on the Hong Kong party. It is not, as a matter of Hong Kong law. However, the commercial reality is that correspondent banking infrastructure, particularly in USD and EUR clearing, may apply those lists regardless of what Hong Kong law requires. The review must distinguish clearly between the legal obligation and the commercial banking risk. Conflating the two produces either unnecessary transaction failures or, more dangerously, an underdocumented banking-risk file that becomes a liability when the payment is queried post-facto.

Consider a mid-market trading group with operations in Hong Kong and a new UAE-incorporated supplier. The supplier's ultimate beneficial owner held a passport from a jurisdiction that appeared on a unilateral sanctions designation list but not on the UN consolidated list. Hong Kong counsel correctly identified that there was no domestic legal prohibition. The compliance file was structured around that finding, with a clear documented analysis of the UN-list position, the banking-channel risk, and the payment-routing options that would minimise correspondent-bank friction. The contract proceeded. A similar transaction handled without that documentation later produced a six-week payment delay when the instruction was flagged by the clearing bank.

The third pattern is the incomplete ownership chain. A UAE entity presents with a clean registry extract, a licensing certificate from a UAE free-zone authority, and a professional corporate profile. The review confirms that no designated person appears in the first layer of the ownership structure. The second and third layers are not examined because the first layer appears clean. This is the most common single failure mode we observe. Complex UAE structures routinely hold assets through one or two offshore layers before reaching the ultimate beneficial owner. The compliance review must trace the ownership chain to the natural-person beneficial owners, not simply to the first registered entity. Where the chain runs through a BVI or Cayman vehicle, the documentation requirements are more onerous and typically require certified extracts from more than one registry.

If an earlier filing, structure, or compliance attempt produced an adverse or stalled result – a blocked payment, an enhanced-due-diligence rejection, or a bank-relationship termination – a second read can identify the documentation gap and the routes still open. Write to us at info@lockhartyip.com to discuss what a structured re-examination would cover.

What does the banking-access analysis actually require?

Banking access is the operational heart of the compliance review. A contract that cannot be settled through accessible payment channels is commercially impaired from inception. The review therefore works backwards from the payment architecture: which banks will process the relevant currency to the UAE counterparty, under what compliance conditions, and what documentation will those banks require before processing the first instruction?

This is not a legal analysis in the conventional sense. It is a mapping exercise that sits at the intersection of legal compliance and operational risk. The starting point is the currency of the contract. USD-denominated payments to a UAE entity will pass through USD correspondent infrastructure, which applies its own screening criteria. EUR-denominated payments follow a parallel path through EUR clearing. Payments in currencies less widely used in Gulf commerce may involve additional correspondent layers, each with its own compliance gate.

The review should produce a documented payment-routing analysis that identifies: the primary banking channel; the compliance documentation that channel will require; any secondary channels available if the primary route encounters friction; and the contractual terms that should be included in the agreement to allocate responsibility if a payment is delayed or blocked for compliance reasons. That last point is frequently omitted from commercial contracts. The failure to address compliance-related payment delay in the contract itself creates a dispute risk that materialises precisely when the banking issue is most acute.

Hong Kong's position as a major international financial centre with direct access to both USD and CNY clearing infrastructure gives it a particular relevance in this analysis. For Asian groups with Mainland China operations, the ability to route a payment in renminbi (RMB, the official currency of the People's Republic of China) rather than USD may reduce correspondent-bank friction while maintaining compliance. The review should model this option where the counterparty's commercial position permits it.

The objection-handler: does the UAE's exit from the FATF grey list change the analysis?

The argument is heard regularly: the UAE was removed from the FATF enhanced-monitoring list in early 2024, so the elevated due-diligence posture that existed during the grey-list period no longer applies. This is a partial reading of the position, and acting on it without qualification creates residual exposure.

What changed with the grey-list exit is the formal FATF classification and the associated signal it sends to supervisory bodies and correspondent banks globally. That change is real and material. It reduced the automatic enhanced-due-diligence triggers that many banks applied to UAE-domiciled counterparties during the grey-list period. It normalised the UAE's position within the FATF mutual-evaluation cycle.

What did not change is the underlying obligation to assess the risk profile of the specific counterparty. FATF standards – and the domestic AML regimes derived from them, including Hong Kong's – require a risk-based approach (an AML methodology that calibrates the intensity of due diligence to the assessed risk level of the specific transaction and counterparty, rather than applying a uniform standard to all dealings). The grey-list exit affects the country-risk component of that assessment. It does not eliminate the obligation to examine the entity, its ownership, and the source of funds for the specific transaction.

A UAE entity with complex offshore ownership, a beneficial owner from a jurisdiction with elevated financial-intelligence risk, or a sector profile in real estate or virtual assets will still attract enhanced scrutiny under a risk-based approach, regardless of the UAE's FATF status. The review must reflect the current risk profile, not the historical regulatory classification. Counsel on our desk would flag any compliance file that relied primarily on grey-list exit as the basis for a reduced due-diligence scope.

Where is the position heading? A practitioner's read on current direction

Several developments in the current regulatory environment are shaping the direction of UAE-related compliance work for Asian groups operating through Hong Kong.

First, the UAE's domestic AML supervisory infrastructure is maturing. The reforms undertaken during and after the grey-list period included enhanced enforcement capacity, stricter beneficial-ownership registration requirements, and greater cooperation with international financial-intelligence units. The practical effect is that a UAE entity that has maintained its domestic compliance obligations will be a better-documented counterparty than was the case several years ago. The availability of reliable, registrar-certified beneficial-ownership information is improving. This is a positive development for the review process, though the documentation must still be obtained and examined rather than assumed.

Second, the correspondent banking environment for UAE-related payments from Hong Kong remains sensitive. The reputational and regulatory cost structure of large correspondent banks continues to drive conservative screening behaviour. This creates a structural gap between the legal position – which in Hong Kong permits the transaction – and the operational reality, which may still produce payment friction if the documentation file is incomplete. The gap is narrowing as the UAE's reforms take effect and as correspondent banks update their risk models, but it has not closed.

Third, the interaction between UAE-related commercial contracts and the virtual-assets sector is growing in complexity. Hong Kong has established a mandatory licensing regime for virtual-asset trading platforms (VATPs, centralised exchanges and related infrastructure subject to licensing by the Securities and Futures Commission under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance, with the regime having commenced 1 June 2023). The UAE has its own virtual-asset regulatory regime, administered through the Virtual Assets Regulatory Authority in Dubai and the Financial Services Regulatory Authority in Abu Dhabi. Where a commercial contract with a UAE entity involves virtual-asset settlement, virtual-asset collateral, or a UAE counterparty in the virtual-assets sector, the compliance review must address both the Hong Kong VATP regime and the UAE licensing position. This is a specialist overlay that requires dedicated analysis. Our Sanctions & AML practice handles this intersection across both jurisdictions.

Fourth, the broader geopolitical context continues to affect the risk profile of UAE-connected transactions. The UAE's commercial and financial links span a wide geography: Mainland China, South Asia, Central Asia, Africa, and the wider Middle East. For a Hong Kong group contracting with a UAE entity, the counterparty's own counterparty risk – the network of the network – is a legitimate consideration in the review. This is not a reason to avoid UAE counterparties. It is a reason to conduct the review with sufficient depth to understand the commercial relationships that sit behind the entity.

For guidance on handling source-of-funds documentation in cross-border commercial files, our AML source-of-funds file guide for Mainland China counterparties sets out the documentation framework we apply, which translates with adaptation to the UAE context. For groups building an internal compliance policy for Asian operations, our internal sanctions and AML policy guide covers the structural requirements for a group-wide approach.

The decision matrix: mapping your position before the contract is signed

The pre-contract compliance review produces a different output depending on the risk profile of the transaction. The following decision-matrix in prose describes the main scenarios our desk encounters.

Situation A: The UAE entity is a well-documented free-zone company with a transparent single-layer ownership structure, a clean UN-list screening result, and a payment channel in a currency with low correspondent-bank friction. The compliance review confirms the CDD file, documents the screening result, and prepares a brief banking-analysis note. The contract proceeds with a standard compliance annex. Risk level: managed.

Situation B: The UAE entity has a multi-layer offshore ownership structure running through a BVI holding vehicle. The first-layer screening is clean; the second and third layers have not yet been examined. The review requires certified beneficial-ownership extracts from the UAE registry and the BVI registry, a source-of-wealth declaration from the ultimate beneficial owner, and a bank-routing analysis before the contract is signed. The compliance file must be completed before execution. Risk level: elevated pending documentation.

Situation C: The UAE entity's beneficial owner holds nationality or residence in a jurisdiction subject to unilateral sanctions measures of a major reserve-currency state. No UN designation applies. Hong Kong law does not impose a domestic prohibition. The review must document the UN-list position clearly, assess the correspondent-banking risk for the specific payment currency, and consider whether a non-USD/non-EUR payment route is viable. The contract should include a compliance-related payment-delay clause. Risk level: banking-channel risk, manageable with documentation and routing analysis.

Situation D: The UAE entity operates in the virtual-assets sector or the real-estate sector, with a payment structure involving virtual-asset settlement or property collateral. Enhanced due diligence applies. The review must cover the UAE licensing status of the entity, the Hong Kong VATP implications if the paying entity in Hong Kong is a regulated platform, and the correspondent-bank position for any fiat-currency legs of the settlement. Risk level: specialist, requiring dedicated layer analysis.

Across all four situations, the common factor is that the compliance review should be completed before the contract is signed and before any payment instruction is issued. The cost of rectification after a payment is blocked or a compliance failure is identified is materially higher – in time, in bank-relationship terms, and in legal exposure – than the cost of the pre-contract review.

Related practices

  • Sanctions & AML – cross-border AML compliance, sanctions screening and counterparty risk across Greater China and the Gulf
  • Corporate Counsel – cross-border commercial contracting, entity structuring and governance for international groups

Frequently asked questions

What is the first step in a compliance review before contracting with the UAE entity?
The first step is a structured counterparty identification exercise: obtaining and verifying the UAE entity's legal name, registration number, free-zone or onshore status, and the identity of its registered directors and shareholders from the relevant UAE registry. This produces the baseline record against which UN-list screening and beneficial-ownership tracing are then conducted. Without a verified legal identity, subsequent screening and source-of-funds work has no reliable anchor. The identification step should be completed before any due-diligence questionnaire is sent to the counterparty, as the questionnaire must be calibrated to the entity's actual legal and ownership profile.
What documents are needed for a compliance review before contracting with the UAE entity?
A standard UAE compliance file covers: a certified copy of the entity's trade licence or incorporation certificate; a beneficial-ownership register extract from the UAE registry; constitutional documents (memorandum and articles of association or equivalent); certified identification for the ultimate beneficial owners to the natural-person level; a source-of-funds or source-of-wealth declaration where the transaction size or risk profile warrants it; and, for entities with offshore holding layers, equivalent certified extracts from the relevant offshore registry. Where the entity is licensed by a UAE financial regulator, a copy of the current licence is also required. The precise document set is calibrated to the risk profile of the transaction and the counterparty; parties should verify the current requirements before relying on any standard list.
What does the route look like for a compliance review before contracting with the UAE entity?
The review follows a defined sequence: legal-identity verification; UN-list and domestic-sanctions screening; beneficial-ownership tracing to the natural-person level; source-of-funds assessment; sector and activity classification; and banking-channel analysis for the payment flows the contract will generate. Each step produces a documented output that together forms the compliance file. The file is prepared before contract execution and updated if the transaction structure or the counterparty's position materially changes before closing. Where a compliance issue is identified, the review produces a risk-mitigation note setting out the available options – additional documentation, alternative payment routing, or contractual risk allocation – rather than a binary pass/fail outcome. Parties should engage counsel early to allow sufficient time for the documentation steps, which typically require cooperation from the counterparty.

Speak with Lockhart & Yip

For a scoped view of your matter, contact info@lockhartyip.com. Discuss your matter →

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@lockhartyip.com.

This site uses only strictly necessary cookies. Non-essential cookies are declined by default. Cookie policy