HONG KONG · EAST ↔ WEST
info@lockhartyip.comResponse within 4 hours (UTC+8)
Discuss your matter
Home/Insights/Disputes & Arbitration
Sanctions & AML

Where a compliance review before contracting with the UAE entity stands now

A compliance review before contracting with the UAE entity. The current cross-border position and what it means in practice. Write to info@lockhartyip.com.

The United Arab Emirates has become one of the most active counterparty jurisdictions for Hong Kong-based trade, treasury and investment deals. The corridor is real, it is growing, and the commercial appetite on both sides is genuine. What has changed is the compliance environment around it. Banks in Hong Kong, London and Frankfurt are applying materially stricter pre-payment scrutiny to UAE-connected counterparties than they were three years ago. That shift did not happen in isolation, and it did not happen because the UAE is a sanctioned jurisdiction – it is not. It happened because the international Financial Action Task Force (FATF, the inter-governmental standard-setter for anti-money laundering and counter-terrorist financing) placed the UAE on its enhanced due-diligence list in 2022, and the downstream effects on correspondent banking have been significant and, in places, durable.

A compliance review before contracting with a UAE entity is a structured cross-border due-diligence exercise that maps the counterparty's ownership, source of funds and banking position against the Anti-Money Laundering and Counter-Terrorist Financing Ordinance, the United Nations Sanctions Ordinance, and the correspondent-bank requirements of the payment channel being used. The UAE was removed from the FATF enhanced-monitoring list in February 2024, but the practical effect of that removal on bank behaviour in Hong Kong and other hubs continues to work through the system. The risk for a contracting party that skips the review is not that the deal is illegal – it is that the payment leg fails, or that the compliance file is subsequently found wanting by a regulator or a correspondent bank.

This analysis sets out the commercial stakes, the governing regime on both sides of the interface, our comparative read on where the residual risk sits, and the practical structure of a review that will hold under scrutiny.

What is commercially at stake in the Hong Kong – UAE corridor?

The Hong Kong – UAE trade and investment corridor spans commodities, real estate capital flows, mid-market M&A, treasury management, and the movement of family-office and private-wealth portfolios. For many Asian groups, a UAE free-zone entity – most commonly formed in the Dubai International Financial Centre (DIFC, a common-law jurisdiction-within-a-jurisdiction governed by DIFC law) or in the Abu Dhabi Global Market (ADGM, a similar common-law financial free zone) – is the chosen holding or trading vehicle for flows into and out of Greater China.

The commercial question is not whether to contract with a UAE entity. The question is whether the payment channel will execute and whether the compliance file will survive a challenge. Banking disruption on a signed contract is not a theoretical risk. Our desk has seen deals where the commercial documentation was unimpeachable but the payment was held, queried or returned because the correspondent bank lacked the AML documentation it needed at the moment it needed it.

What is at stake, then, is not primarily regulatory liability – though that exists. It is deal execution. A compliance review done before signing, rather than after the first payment is queued, is the instrument that separates a deal that closes on schedule from one that does not close at all.

How does the governing regime operate across the two systems?

Hong Kong implements the Anti-Money Laundering and Counter-Terrorist Financing Ordinance as the primary domestic instrument. That Ordinance imposes customer due-diligence and ongoing-monitoring obligations on designated non-financial businesses and professions (DNFBPs) and on banks. The Ordinance adopts the FATF recommendations as its functional standard. It requires enhanced due diligence where a business relationship involves a counterparty from a jurisdiction identified as presenting higher risk – a category that, until February 2024, expressly included the UAE by reference to the FATF grey list.

Layered above the Ordinance is the United Nations Sanctions Ordinance, which gives domestic effect in Hong Kong to UN Security Council sanctions. The UAE is not a sanctioned jurisdiction under any UN regime. Hong Kong does not give domestic legal effect to the unilateral measures of other states – including the US Office of Foreign Assets Control or EU sanctions instruments – though correspondent banks operating in US-dollar or euro payment systems will apply those regimes to their own transactions regardless of Hong Kong's posture.

The practical effect of that split is precisely where the cross-border interface bites. A Hong Kong company contracting with a UAE entity may have a clean position under Hong Kong and UN law, yet still face a payment block applied by its correspondent bank in New York or Frankfurt on the basis of that bank's own OFAC or EU-sanctions compliance programme. That block is not a Hong Kong legal problem; it is a banking-channel problem. But it produces the same commercial outcome – a failed payment – and the compliance file is the instrument that prevents it.

On the UAE side, the Central Bank of the UAE and the Emirates' financial intelligence unit, the UAE Financial Intelligence Unit (UAE FIU), supervise a domestic AML regime that has been substantially overhauled since 2022. The ADGM and DIFC each operate their own financial-services regimes under, respectively, the ADGM Financial Services Regulatory Authority (FSRA) and the Dubai Financial Services Authority (DFSA). An entity incorporated in either free zone is subject to that free zone's regulatory regime rather than, or in addition to, the UAE onshore framework. For a counterparty-diligence exercise, the jurisdiction of incorporation within the UAE matters considerably: a DIFC or ADGM entity will typically have more accessible regulatory records and a cleaner documentation trail than an onshore UAE entity or a Jebel Ali Free Zone (JAFZA) structure.

What did the FATF grey-listing mean in practice, and does removal change the analysis?

The UAE's placement on the FATF enhanced-monitoring list in March 2022 triggered a formal obligation on financial institutions in FATF-member jurisdictions – including Hong Kong – to apply enhanced due diligence to transactions involving UAE counterparties. That meant, in practice, deeper beneficial-ownership verification, more detailed source-of-funds enquiry, and, in many cases, senior-management sign-off on individual transactions.

The UAE was formally removed from the grey list in February 2024. That removal matters for the formal regulatory position: the express enhanced-due-diligence obligation triggered by FATF classification no longer applies by that mechanism alone. However, removal is not a switch that resets bank behaviour instantaneously. Correspondent banks typically maintain their own risk-appetite frameworks, and many have retained UAE-specific controls that were implemented in 2022 and have not been fully unwound.

The practical consequence is that a compliance review for a UAE counterparty in late 2025 or 2026 must be calibrated to where the relevant bank actually sits on UAE risk, not where FATF formally puts the UAE. We regularly see clients who have assumed that grey-list removal meant the enhanced-diligence requirement had disappeared, only to find their correspondent bank still applying a UAE-specific supplemental questionnaire. The answer is not to avoid the bank's process; it is to have the documentation ready before the bank asks.

That calibration – understanding the specific correspondent bank's current UAE risk appetite and preparing the file accordingly – is one of the elements a structured pre-contract review should address. The review is not a regulatory formality. It is a deal-execution tool.

How does the review actually work? A cross-border sequence

A pre-contract compliance review for a UAE entity counterparty has a defined structure. The sequencing matters: gaps discovered late add cost and, more importantly, delay the signing timeline.

The first step is counterparty identification and ownership mapping. For a UAE entity, this means obtaining the trade licence, the certificate of incorporation, and the beneficial-ownership register or equivalent disclosure from the relevant registry. For a DIFC or ADGM entity, registry records are more readily accessible and the regulatory framework is familiar to international compliance teams. For an onshore UAE entity or a multi-layer UAE structure, the ownership map may require notarised translations and additional primary-source verification.

The second step is a sanctions and watchlist screen against UN consolidated lists, OFAC's Specially Designated Nationals list, the EU consolidated list, and any other list material to the payment channel being used. This is not an optional step, even though Hong Kong law does not require OFAC compliance. If the payment will move through a US-dollar correspondent account, the account-holding bank will apply OFAC regardless of the payer's own legal obligations.

The third step is source-of-funds and source-of-wealth analysis. This is the step most often skipped, and it is the step most often raised by banks as the reason a payment is queried. For a UAE trading entity, this typically means reviewing audited accounts, a bank-confirmation letter, and a narrative of the entity's commercial activities. For a UAE family-office or holding structure, it may mean tracing the ultimate beneficial owner's wealth back to a documented event – a sale, an inheritance, a prior business – and having that documentation in a form the bank can review.

The fourth step is payment-channel assessment. The parties should agree at the contracting stage which currency and which banking corridor the payment will travel through. A US-dollar payment between a Hong Kong company and a UAE entity will pass through at least one US-dollar correspondent bank. A dirham-denominated payment is a materially different risk profile. That choice is a structuring decision, and it should be made before the contract is signed, not at the moment of payment.

The fifth step is documentation and file assembly. The compliance file should be assembled before signing and held in a form that can be produced to the Hong Kong company's own bank, to the correspondent bank, or to a regulator, on short notice. A file that exists only in email threads is not a file. A file that was assembled after the first payment was queried is a file with a structural weakness.

Where does the risk actually sit in a Hong Kong – UAE transaction?

The risk in this corridor sits in three distinct places, and conflating them leads to the wrong response.

The first risk is regulatory: a Hong Kong entity that fails to conduct adequate customer due diligence on a UAE counterparty – or fails to document that it did – is exposed under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance. That exposure sits with the designated entity: typically the Hong Kong company's bank, its external legal adviser in the context of a qualifying transaction, or the company itself if it falls within the DNFBP categories. The risk is a regulatory finding and, in serious cases, a prosecution. It does not require that the underlying transaction was unlawful; a failure of process is sufficient.

The second risk is banking: a payment that cannot be processed because the compliance file is incomplete or because the counterparty appears on a watchlist. This risk materialises at the moment the bank runs its own checks, which is typically at the point of payment instruction. A failed payment is a contractual breach risk if the payment was due; it is also a deal-death risk if the counterparty is not willing to wait. Banking disruption of this kind is reversible if the underlying diligence is sound and the documentation can be produced quickly. It is much harder to remedy if the diligence was not done.

The third risk is reputational: association with a counterparty that is subsequently found to have a sanctions, corruption or financial-crime problem. This risk cannot be eliminated by a compliance review, but it can be managed. The purpose of a pre-contract review is not to certify that the counterparty is clean; it is to demonstrate that the contracting party took reasonable steps, proportionate to the risk, to understand who it was dealing with and where the money came from.

In our cross-border practice, the third risk is the one that is most consistently underestimated. Clients focus on whether the payment will go through. The question of what happens to the relationship – and to the client's own banking relationships – if the counterparty subsequently becomes the subject of an enforcement action is a question that deserves equal attention before signing.

What foreign counsel, and some in-house teams, get wrong

The most common error we see on this corridor is treating the compliance review as a box-ticking exercise rather than a substantive analysis. A review that consists of a sanctions-screen printout and a copy of the trade licence is not a compliance review. It is a partial screen. If that is what the contracting party's file contains, it will not survive scrutiny by a correspondent bank or a regulator.

The second error is scoping the review to the wrong legal system. Some in-house teams focus exclusively on the UAE side of the transaction – they verify that the UAE entity is properly licensed and that it is not on a UAE watchlist – without addressing the Hong Kong AML obligations or the payment-channel risks arising from the correspondent bank's own compliance programme. The review must span both systems and the payment corridor between them.

The third error is timing. A compliance review commissioned after the term sheet is signed but before the definitive agreement is in place has the right idea but is often too late to influence the payment-channel decision. The payment-channel choice – currency, banking corridor, correspondent-bank relationship – is a structuring question that should be addressed alongside the commercial terms, not after them.

The fourth error is documentation discipline. The review is only as good as the file that records it. An oral conclusion that the counterparty looks acceptable, delivered by outside counsel in a meeting, is not a defensible compliance position. The file must contain the primary-source documents, the screen results, the source-of-funds analysis, and a dated record of the steps taken and the conclusions reached.

A decision read: situation, instrument, route, timing, risk

Situation A: A Hong Kong trading company intends to purchase goods from a UAE onshore entity. The payment will be US-dollar denominated, routed through a Hong Kong bank with a US-dollar correspondent relationship. The risk profile is elevated by the US-dollar corridor and the onshore UAE structure. The instrument is the Anti-Money Laundering and Counter-Terrorist Financing Ordinance and the correspondent bank's own OFAC compliance programme. The route is a full pre-contract review including ownership map, source-of-funds analysis, OFAC and UN screen, and payment-channel confirmation. The timing is before the contract is signed. The residual risk, if the file is complete, is low. The residual risk if the file is incomplete is a blocked payment and a regulatory exposure.

Situation B: A Hong Kong holding company intends to enter a joint-venture with a DIFC-incorporated entity owned by a UAE family office. The payment flows are multi-directional: capital contributions, distributions, management fees. The risk profile is shaped by the beneficial-ownership question – a UAE family office may have a complex multi-jurisdictional ownership chain – and by the variety of payment flows. The instrument is the same Ordinance, but the source-of-wealth dimension is more prominent than in a simple trade transaction. The route is a structured pre-contract review with a specific source-of-wealth component for the ultimate beneficial owners. The timing is before the joint-venture agreement is signed. The risk, if the review is deferred, is that the first capital-contribution payment triggers the bank's enhanced-due-diligence process in the middle of a deal with closing conditions.

Situation C: A Hong Kong professional-services firm is retained by a UAE entity to provide advisory services. Payment is in USD. The firm falls within the DNFBP category under the Ordinance. The instrument is the Ordinance's customer-due-diligence requirements as they apply to DNFBPs. The route is a client-acceptance review under the firm's own AML policy, which must meet the Ordinance's standard. The timing is before the engagement begins. The risk of non-compliance is not the payment – it is the firm's own regulatory standing.

The common thread across all three situations is that the review must be completed before the point of commitment, not after it.

Where is this heading? Our read on the current position

The direction of travel is towards normalisation of the UAE-Hong Kong corridor, but not towards deregulation of it. The UAE's removal from the FATF grey list in February 2024 is a meaningful signal. The UAE has implemented substantial institutional reforms to its AML regime, its beneficial-ownership registers, and its financial-intelligence infrastructure. Those reforms are real, and they matter for a counterparty-diligence exercise: the primary-source documentation that a compliance review depends on is materially better in the UAE today than it was in 2022.

What is not changing is the fundamental structure of the obligation. The Anti-Money Laundering and Counter-Terrorist Financing Ordinance, and the FATF recommendations it implements, require ongoing risk-based due diligence on counterparties regardless of whether they are in a grey-listed jurisdiction. The UAE's removal from the grey list reduces the formal enhanced-due-diligence trigger for that specific reason; it does not reduce the baseline obligation. A counterparty is not low-risk simply because its jurisdiction is not on a list.

The correspondent-banking environment will continue to normalise, but at its own pace. Some banks have already unwound their UAE-specific supplemental requirements. Others have not. The practical implication for a contracting party is that it cannot assume which bank-specific posture it will encounter at the point of payment. The file must be ready before that moment arrives.

We also note a developing area of attention: the interaction between UAE-based virtual-asset businesses and Hong Kong's own virtual-asset trading platform licensing regime, which commenced on 1 June 2023. Where a UAE counterparty is a virtual-asset service provider or holds digital assets as part of its balance sheet, the compliance review has an additional dimension. The source-of-funds analysis must address the origin of the virtual-asset holdings, the regulatory status of the UAE entity's virtual-asset activities, and the position of any Hong Kong bank that would receive a payment connected to those assets. This intersection of the UAE corridor with Hong Kong's developing virtual-asset regime is one of the areas our desk is watching most closely.

The sequence above describes the standard position. Your matter turns on the documents, the jurisdictions actually engaged, and the order of steps – which is where the route is won or lost. For a structured assessment of your compliance review position across Hong Kong and the UAE, write to us at info@lockhartyip.com.

If an earlier engagement, a prior payment disruption, or a stalled counterparty-acceptance process has left your compliance file incomplete, a second read can identify the gaps and the steps still available. Email us at info@lockhartyip.com.

Related practices

  • Sanctions & AML – cross-border AML compliance, sanctions screening and counterparty due diligence
  • Corporate Counsel – cross-border contract structuring and entity-level compliance support

Frequently asked questions

How does the cross-border element affect a compliance review before contracting with the UAE entity?
The cross-border element means the review must address two distinct legal regimes and the payment corridor between them. Under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance, the Hong Kong contracting party carries its own due-diligence obligation regardless of what the UAE entity has done. The payment channel – particularly where US-dollar correspondent banks are involved – adds a third layer of compliance scrutiny that operates independently of both the Hong Kong and UAE legal requirements. A review scoped to one system only is structurally incomplete.
What documents are needed for a compliance review before contracting with the UAE entity?
The core documentary set covers: the trade licence and certificate of incorporation; the beneficial-ownership register or equivalent primary-source disclosure; identification documents for ultimate beneficial owners; audited financial statements or equivalent source-of-funds evidence; and a confirmation of the banking corridor to be used. For a DIFC or ADGM entity, regulatory registry records supplement this set. For a UAE onshore entity, notarised translations and additional primary-source verification are typically required. The exact scope depends on the risk profile of the specific transaction and counterparty.
How long does a compliance review before contracting with the UAE entity usually take?
The timeline depends on counterparty responsiveness and document availability. Where a DIFC or ADGM entity with accessible registry records is involved and the counterparty is co-operative, a review can be completed within one to two weeks of receiving the document set. A complex onshore UAE structure with a multi-jurisdictional ownership chain will take longer. The most reliable way to manage the timeline is to initiate the review as early as possible in the commercial negotiation – before the term sheet rather than after it.

Speak with Lockhart & Yip

For a scoped view of your matter, contact info@lockhartyip.com. Discuss your matter →

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@lockhartyip.com.

This site uses only strictly necessary cookies. Non-essential cookies are declined by default. Cookie policy