How to approach a compliance review before contracting with the UAE entity
A compliance review before contracting with the UAE entity. A practical guide for in-house counsel. The Hong Kong angle in focus. Write to info@lockhartyip.com.
A contract with a counterparty in the United Arab Emirates can move fast. Term sheets arrive, commercial pressure builds, and the compliance queue gets shorter than it should. For groups operating through Hong Kong – and for any cross-border desk dealing with Greater China, Gulf, and European capital simultaneously – the cost of a thin pre-contract file is not just reputational. It is banking access, payment-channel risk, and, in the event of a dispute, the enforceability of the agreement itself.
A compliance review before contracting with a UAE-based entity is a structured sequence of source, counterparty, and instrument checks, governed by the Anti-Money Laundering and Counter-Terrorist Financing Ordinance and the United Nations Sanctions Ordinance on the Hong Kong side, and by UAE federal AML legislation and the UAE Central Bank's supervisory framework on the counterparty's side. The review is completed before execution, not after, and its output is a documented file that survives correspondent-bank scrutiny.
This guide sets out the practical steps in the order they run, the gate at each stage, the most common error our desk sees, and a short decision checklist to use before signature. It is written for in-house counsel and compliance officers at groups with a Hong Kong nexus contracting into the Gulf.
Why the Hong Kong–UAE corridor creates a distinct compliance question
The Hong Kong–UAE trade and investment corridor is substantial and, on the compliance side, subject to two separate regulatory architectures that do not mirror each other. Understanding the asymmetry is the starting point for any review.
Hong Kong implements United Nations sanctions under the United Nations Sanctions Ordinance. It does not give domestic effect to the unilateral measures of other states. That is a fixed and well-established position. The UAE, by contrast, operates its own federal sanctions list, maintained by the UAE Executive Office of Anti-Money Laundering and Counter Terrorism Financing, alongside its implementation of UN measures. A UAE entity that is clean against UN lists may still carry correspondent-bank exposure if it appears on a unilateral list maintained by a jurisdiction whose currency or clearing infrastructure the transaction uses.
That last point is where most cross-border contract reviews stall. The legal compliance question for a Hong Kong-law contract is answered by Hong Kong rules. The banking question – whether the payment will clear, whether the correspondent bank will process the transfer, whether the beneficiary's account will accept the credit – is answered by a different and often overlapping set of considerations. Our desk sees this intersection repeatedly on transactions routed through Hong Kong but settled in US dollars or euros. The compliance file must address both layers, not just the first.
The UAE was removed from the Financial Action Task Force (FATF, the inter-governmental standard-setter for AML and counter-terrorist financing) grey list in February 2024, following a period of enhanced monitoring. That change is commercially significant. It reduced the automatic additional due-diligence burden that FATF grey-list status imposed on counterparts in many banking jurisdictions. However, removal from the grey list does not eliminate the need for a structured review. The underlying substance requirements – source of funds, beneficial ownership, purpose of the transaction – remain in place under both Hong Kong's and the UAE's own rules.
Step one: define the counterparty and its ownership chain
The first gate in any compliance review is knowing precisely who the counterparty is. In the UAE, an entity may be incorporated in the mainland UAE (under one of the federal company types), in one of the free zones (such as the DIFC or the ADGM, each of which operates under its own legal regime), or in an offshore centre. These distinctions matter for document collection and for understanding the supervisory regime the entity is subject to.
The documents to collect at this step are: the certificate of incorporation or equivalent founding instrument; the current memorandum and articles, or equivalent constitutional document; a register of directors; and, critically, a beneficial-ownership declaration tracing the ownership chain to the natural-person ultimate beneficial owners. Where the entity is a free-zone company in the Dubai International Financial Centre (DIFC, which operates under English common-law principles) or the Abu Dhabi Global Market (ADGM, also a common-law centre), the corporate-registry filings tend to be more accessible. For mainland UAE entities, official extracts from the relevant emirate-level registry are the primary source.
The gate at this step: the review does not proceed to document analysis until a complete ownership chain is in hand, all the way to the natural persons who own or control the entity above any agreed threshold. If the counterparty resists producing this, that resistance is itself a material fact for the file.
One practical point for Hong Kong-based compliance teams: the Significant Controllers Register requirement under the Companies Ordinance (Cap. 622) – which applies to Hong Kong-incorporated companies and has been in force since 1 March 2018 – provides a familiar analogue for what is being asked of the UAE counterparty. The principle is the same: trace control to natural persons. Framing the request in those terms often moves the process forward.
Step two: screen against applicable sanctions lists and risk indicators
Screening runs once the ownership chain is documented. The relevant lists for a Hong Kong-anchored review include the UN consolidated sanctions list, the Hong Kong-specific designations made under the United Nations Sanctions Ordinance, and any sector- or geography-specific designations that apply to the particular transaction.
The screening is not a single database click. It is a process with three distinct sub-steps: a name-match review against the relevant lists; a review of adverse-media and regulatory-action sources for the entity and its beneficial owners; and a country-risk assessment for any intermediate jurisdiction in the ownership chain. Where the ownership chain passes through a jurisdiction with elevated FATF risk indicators, that leg requires documented treatment, not just a checkbox.
For the UAE specifically, the post-grey-list position means the automatic enhanced-due-diligence trigger that applied to UAE counterparties under many institutions' internal policies has moderated. That said, sector exposure matters. A UAE entity in real estate, precious metals, virtual assets, or certain financial-services segments carries a different inherent risk profile than a manufacturing counterpart. The sector risk feeds directly into the depth of the review and the source-of-funds questions at step three.
What does the Hong Kong AML regime require at this point? The Anti-Money Laundering and Counter-Terrorist Financing Ordinance imposes customer due diligence (CDD) obligations on specified financial institutions and designated non-financial businesses and professions (DNFBPs, which include legal practitioners advising on certain transactions). For a Hong Kong-registered company that is not itself a regulated entity, the obligation is framed differently – but the consequence of proceeding on thin diligence into a contract is exposure at the banking layer, not just the regulatory one. Correspondent banks and payment processors apply their own CDD frameworks, and a payment instruction attached to a poorly documented contract is a common trigger for a hold or a return.
The gate at this step: no person on any applicable sanctions list, and no unresolved adverse-media finding that would preclude banking clearance, may proceed to contract. Where a match is ambiguous, the ambiguity is resolved before execution – not after.
Step three: document source of funds and purpose of the transaction
The third step addresses the substance of the commercial relationship. Source-of-funds documentation is not only a regulatory requirement in certain contexts; it is the strongest signal a compliance file can send to a downstream institution that the transaction is what it appears to be.
The documents at this step depend on the nature of the transaction. For a trade contract, the review covers the business rationale, the underlying goods or services, the pricing (is it consistent with market rates?), and the payment terms (do the payment flows match the commercial logic?). For an investment or financial arrangement, the review covers the source of the investment capital and the commercial purpose of the structure. For a service agreement, the review covers what service is actually being provided, to whom, and why the payment flows in the direction it does.
This is the step where the cross-border element becomes most concrete. A transaction routed from a UAE entity through Hong Kong to a Mainland China beneficiary, or vice versa, involves three separate compliance environments. The question is not only whether each node passes its own rules, but whether the overall pattern of flows is consistent with the stated purpose. Correspondent banks operating in US dollars or euros routinely apply their own know-your-customer (KYC, the process of verifying the identity and risk profile of a counterparty) overlay to precisely this kind of multi-node transaction. The file assembled at this step is what the group's bank – or the counterparty's bank – will ask to see when the payment instruction arrives.
To see how this step operates in the context of a broader deal, the analysis of sanctions due diligence for a deal touching the UAE works through a comparable sequence at transaction level.
The gate at this step: the source of the counterparty's funds must be documented to a standard consistent with the risk profile established at step two. A high-risk sector profile requires more documentation, not the same amount. Where the source cannot be adequately documented, the transaction does not proceed.
What foreign counsel often get wrong – and how the sequence avoids it
The most common error we see on the Hong Kong desk is sequencing. Specifically: the legal review is completed – the contract is negotiated, the terms are agreed, the execution is scheduled – and only then is the compliance file assembled. By that point, the commercial pressure to close is at its maximum, and any finding that should have stopped the deal at step one is instead managed around. That is not compliance. It is a documentary exercise designed to produce a file that looks adequate, regardless of what it found.
The second common error is jurisdictional narrowing. A compliance team reviews the UAE entity against Hong Kong rules and UN lists, concludes that the review is complete, and proceeds. The contract then produces a payment instruction in US dollars, cleared through New York, on behalf of a beneficiary whose name appeared in an adverse-media search that was not run. The payment is held. The contract is in dispute. The compliance file, which was accurate as far as it went, did not go far enough.
The third error is treating the UAE as a single jurisdiction. The DIFC and ADGM operate distinct legal regimes with their own courts, their own company-law rules, and their own AML supervisory frameworks. A mainland UAE entity is subject to federal and emirate-level regulation. A free-zone entity outside the two financial centres is subject to its own free-zone rules. The document-collection requirements at step one differ across these categories, and a review that applies a single template to all of them will have gaps.
The sequence in this guide – ownership chain first, screening second, source of funds and purpose third – is designed to prevent each of these errors. The gate at each step means that a problem discovered early stops the process before more time and legal cost is invested in the wrong direction. For a comparable treatment in a different Gulf-corridor context, see the guide to compliance review before contracting with a Cyprus entity, which addresses the European side of a similar bilateral structure.
For a comprehensive overview of the firm's approach to this area, the Sanctions & AML practice page sets out the full scope of what that work covers.
How the banking and payment-channel question runs alongside the legal review
A compliance review that satisfies the legal requirements but ignores the payment-channel question is only half a review. This is the commercial reality of the Hong Kong–UAE corridor, and it is worth addressing directly.
The relevant dynamic is straightforward. A Hong Kong company contracts with a UAE entity. The payment terms require a wire transfer. The Hong Kong company's bank is a major international institution whose correspondent-banking relationships depend on its own compliance posture with respect to its regulators – which may include regulators in jurisdictions whose unilateral sanctions lists cover categories of persons or sectors relevant to the UAE. The bank applies its own internal framework, which may be more conservative than what Hong Kong law requires. The payment instruction is reviewed. The file attached to the transaction is assessed. If the file is thin, the payment is held pending further information, or declined.
This is not a legal dispute in the traditional sense. There is no court, no judgment, no enforcement proceeding. It is a banking-operations issue that creates a commercial standstill and, in some structures, a contractual default. Preventing it is entirely possible, but it requires that the compliance file be assembled with the correspondent-bank reviewer in mind, not just the regulatory-compliance reviewer.
In practice, that means the file should be coherent as a narrative: who is the counterparty, who ultimately controls it, where does its money come from, what is the commercial purpose of this transaction, and why is the payment flowing in this direction at this amount. Each of those questions has a document that answers it. The review assembles those documents in order, with any gaps identified and addressed before the payment instruction is issued.
A micro-scenario illustrates the point. A mid-market European trading group with a Hong Kong holding entity entered a supply contract with a UAE mainland entity in a commodities sector carrying elevated sector risk (late 2026). The initial compliance review was completed against UN lists only; the beneficial-ownership chain was two levels deep; the source-of-funds documentation covered the UAE entity's most recent financial statements but did not address a change-of-ownership event from the prior year. The first payment instruction was held by the correspondent bank for six weeks. We were instructed to rebuild the file. The ownership chain was traced to the natural-person beneficial owner through a re-domiciled holding entity; the change-of-ownership event was documented; a source-of-funds narrative was prepared. The payment cleared on the second presentation. The contract was not terminated, but the delay had commercial consequences that a complete initial review would have avoided.
Decision checklist before signature
The following checklist captures the pre-signature state that a compliance review for a UAE counterparty should reach. It is not a substitute for the full review; it is the final gate before the file is closed and the contract is executed.
Counterparty identity: the entity's full legal name, registration number, and jurisdiction of incorporation have been confirmed against the official registry. The entity type – mainland UAE, DIFC, ADGM, or other free-zone – has been identified and the applicable legal regime noted.
Ownership chain: the beneficial-ownership structure has been traced to the natural-person ultimate beneficial owners. The ownership declaration has been received and reviewed. Any intermediate holding jurisdictions have been identified and assessed for additional risk indicators.
Sanctions screening: the entity, its directors, and its ultimate beneficial owners have been screened against the UN consolidated list and any other applicable list. No match has been found, or any potential match has been assessed and resolved with documented reasoning. The screening is dated within a short period of the intended execution date.
Adverse media: a structured adverse-media review has been completed for the entity and its beneficial owners. Any findings have been assessed, documented, and resolved or escalated.
Source of funds: the source of the counterparty's funds for this transaction has been documented to a standard consistent with the entity's risk profile. For elevated-risk sectors, the documentation goes beyond financial statements to address the origin of the relevant capital.
Transaction purpose: the commercial purpose of the transaction, the pricing, and the direction of payment flows have been reviewed for consistency with the stated business rationale. Any anomaly has been noted and resolved.
Payment channel: the intended payment route has been reviewed for correspondent-bank exposure. Where the transaction involves a currency or clearing system subject to unilateral sanctions measures, the file has been prepared with that review in mind.
Documentation: the full file is assembled, indexed, and retained before signature. The file is not assembled retroactively.
Where any item on this checklist cannot be completed before the proposed execution date, the options are: extend the timeline to complete the review; seek additional documents or representations from the counterparty; or, where the gap cannot be resolved, reassess the transaction. Proceeding with an incomplete file is a decision, not an oversight, and it should be treated as such.
Practical read: the decision a GC faces at the start of this process
Before a compliance review begins, the general counsel or compliance officer faces a framing question: is this review being conducted to satisfy a regulatory obligation, to protect banking access, or both? The answer determines the depth and the output format of the work.
A review conducted purely for regulatory compliance, covering only what Hong Kong's AML rules require of the specific type of entity involved, may be technically adequate and commercially insufficient. A review conducted for banking-access purposes – designed to produce a file that will pass a correspondent-bank CDD review – will generally exceed the regulatory minimum and produce a more useful document.
In our cross-border practice, the two objectives are best treated as aligned rather than sequential. A file that satisfies both the regulatory and the banking-access tests is the standard a well-run compliance review should reach. That standard is achievable on a reasonable timeline when the process starts before the contract is signed, the ownership-chain documents are requested early, and the sector risk profile is assessed at the outset rather than discovered mid-process.
The specific challenge for Hong Kong-based groups is that the Anti-Money Laundering and Counter-Terrorist Financing Ordinance imposes its own CDD obligations, and those obligations interact with – but do not replicate – what the group's bank will require. Counsel on our desk regularly map these two sets of requirements together so that the review output satisfies both in a single pass rather than generating two separate files that address different questions.
The sequence above describes the standard position. Your matter turns on the documents, the jurisdictions actually engaged, and the order of steps – which is where the route is won or lost. For a structured assessment of your compliance position across the Hong Kong–UAE corridor before the contract is signed, write to us at info@lockhartyip.com.
Related practices
- Sanctions & AML – cross-border AML review, sanctions screening and counterparty compliance files
- Corporate Counsel – contract structuring, cross-border governance and pre-execution legal review
Frequently asked questions
What documents are needed for a compliance review before contracting with the UAE entity?
Which jurisdiction's law applies to a compliance review before contracting with the UAE entity?
How does the cross-border element affect a compliance review before contracting with the UAE entity?
Speak with Lockhart & Yip
For a scoped view of your matter, contact info@lockhartyip.com. Discuss your matter →
Related
- Sanctions Aml
- Compliance Review Before Contracting Cyprus Entity Cyprus Analysis
- Sanctions Due Diligence Deal Touching Uae Uae Analysis
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@lockhartyip.com.