Matter note: a compliance review before contracting with the UAE entity
A compliance review before contracting with the UAE entity. An anonymised matter and the route foreign counsel took. Write to info@lockhartyip.com.
A single contractual relationship with a counterparty in the UAE can turn a straightforward cross-border transaction into a multi-week compliance exercise. Not because the counterparty is problematic, but because the institutional gatekeepers – correspondent banks, payment processors, clearing chains – apply their own risk filters before funds move. For a Hong Kong group entering a commercial relationship with a UAE entity, the gap between legal permissibility and operational readiness is where deals stall.
A compliance review before contracting with a UAE counterparty involves assessing the counterparty's regulatory status, ownership, and sanctions exposure under both the Hong Kong AML regime – governed by the Anti-Money Laundering and Counter-Terrorist Financing Ordinance – and the correspondent banking standards of the payment channels the parties intend to use. The review is not a formality: it is the step that determines whether the banking relationship will function once the contract is signed.
This note describes an anonymised matter our desk handled involving a Hong Kong-incorporated operating company that wished to contract with a UAE-based entity for the supply of specialised services. It covers the structure of the problem, the route taken, the turning point, and the lesson that applies across similar situations.
The situation and the constraint
The client was a Hong Kong-incorporated company with an established trading relationship in Asia and a shareholder base distributed across two jurisdictions. It had identified a UAE counterparty as a preferred partner for a services engagement. The commercial terms had been negotiated in outline. Both sides wanted to move quickly.
The constraint arrived before the contract was signed. The client's principal correspondent bank, a large institution clearing USD through the United States, flagged the proposed payment corridor as requiring enhanced review. The bank's own financial crime compliance unit had questions about the ownership chain of the UAE entity and the economic substance of the contemplated transaction. Until those questions were answered to the bank's satisfaction, the payment channel would not function.
This is a pattern our desk sees regularly. The legal permissibility of the transaction – under both Hong Kong law and the law of the UAE – was not in question. The United Nations sanctions regime applicable in Hong Kong did not touch the counterparty or its principals. The issue was the compliance standards of the institutional channel through which the commercial relationship would operate. Those standards are not a matter of law in any single jurisdiction; they reflect the risk appetite and correspondent-banking obligations of the institutions in the clearing chain.
What the client needed was not permission to transact. It was a documented compliance position that would satisfy the institutional intermediaries and allow the banking relationship to function.
The cross-border interface: Hong Kong and the UAE
The Hong Kong position is governed by the Anti-Money Laundering and Counter-Terrorist Financing Ordinance, which imposes customer due diligence (CDD – the process of identifying and verifying the identity and ownership of a counterparty) obligations on financial institutions and designated non-financial businesses. Hong Kong implements United Nations sanctions. It does not give domestic effect to the unilateral measures of other states, including the extraterritorial sanctions programmes of the United States or the European Union. That distinction matters, but it does not resolve the banking-channel problem.
The UAE occupies a specific position in international compliance assessments. It was placed on the Financial Action Task Force (FATF – the international standard-setter for anti-money laundering and counter-terrorism financing measures) grey list in 2022 and was removed from that list in 2024 following a series of legislative and institutional reforms. The removal was a significant development. But international correspondent banks were slower to update their internal risk frameworks than the FATF's public position. At the time of this matter, a number of tier-one clearing institutions were still applying enhanced-scrutiny procedures to UAE-connected payment flows.
The result was a structural gap: a transaction that was legally permissible on both sides of the corridor, and that did not engage any UN sanctions designation, was nonetheless subject to a practical compliance barrier at the institutional level. Bridging that gap required a documented file, not a legal opinion on permissibility alone.
The issue and the route chosen
The core issue had two components. First, the ownership chain of the UAE entity was opaque at the point the client's bank reviewed it. The entity had an intermediate holding structure involving a free-zone company and an ultimate beneficial owner whose public-registry footprint was limited. Free-zone entities in the UAE are subject to their own registration regimes, and the information available on public registries did not satisfy the bank's CDD threshold without supplementary documentation.
Second, the nature of the services being procured was not self-evidently mainstream. The services were legitimate and commercially rational, but their description in the draft contract was insufficiently precise to permit a compliance officer at the bank to categorise the transaction cleanly. Ambiguity in the transaction description is a significant risk factor in payment-channel reviews. It does not indicate wrongdoing; it generates delay and escalation.
The route chosen addressed both components in sequence. We were engaged to prepare a structured compliance file for the client to present to its bank, and to advise on the due diligence steps the client itself needed to carry out under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance as a Hong Kong company entering into a commercial relationship of this kind. The advice was compliance-centred throughout. There was no question of structuring the transaction to defeat any AML or sanctions obligation.
The steps were: a counterparty identification exercise collecting the ownership chain of the UAE entity to the ultimate beneficial owner level; a sanctions screening against the UN consolidated list and the relevant HKSAR designations; a source-of-funds assessment for the first payment tranche; and a transaction narrative for the bank's compliance file explaining the commercial rationale, the services being procured, and the way in which the pricing reflected market norms. Each element was documented. The file was structured to be readable by a bank compliance officer who had no prior context on the relationship.
The sequence above describes the standard position. Your matter turns on the documents, the jurisdictions actually engaged, and the order of steps – and it is in that detail that the route is won or lost. To discuss how this structure applies to your cross-border position, contact info@lockhartyip.com.
The sequence and the turning point
The work began with the ownership chain. The UAE entity's directors provided a corporate registry extract from the relevant free-zone authority, a certificate of incumbency, and a register of beneficial owners – the formal ownership record maintained at the entity level – together with copies of the ultimate beneficial owner's identification documents. That documentation, taken alone, was sufficient for the client's own CDD file under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance. It was not, by itself, enough for the correspondent bank's enhanced-review process.
The turning point came at the second stage: the transaction narrative. Our desk prepared a concise memorandum, addressed to the bank's financial crime compliance unit, that described the commercial relationship in plain terms, identified the regulatory basis on which Hong Kong assessed the UAE corridor, noted the FATF position, and documented the sanctions-screening outcome. The memorandum cross-referenced the ownership documentation and set out the expected payment flow, the frequency of transactions, and the commercial rationale for the pricing structure. It was direct and factual. It did not advocate; it evidenced.
The bank accepted the file without further escalation. The payment channel was released. The contract was signed within a week of the file being submitted.
Why did that step make the difference? Because the bank's compliance unit was not assessing legal permissibility in isolation. It was assessing whether the relationship had been properly understood and documented by the client. A well-constructed compliance file demonstrates that the client has carried out its own obligations under the AML regime and is not relying on the bank to be the sole checkpoint in the chain. That shift in framing – from "is this permitted?" to "has this been properly assessed by the client?" – changes the dynamic of the institutional review.
If an earlier filing, structure, or enforcement attempt produced an adverse or stalled result, a second read can identify the strategic error and the routes still open. Write to info@lockhartyip.com to discuss the position.
The qualitative outcome and the transferable lesson
The matter resolved in the client's favour. The commercial relationship proceeded. The compliance file remained on record for subsequent transactions with the same counterparty, which reduced the review burden on later payment runs.
The transferable lesson is not specific to the UAE corridor or to any particular counterparty type. It applies wherever a Hong Kong-based entity is contracting with a counterparty in a jurisdiction that carries elevated institutional-risk perception – whether that perception is current, residual, or based on sector rather than geography.
The lesson has three elements. First, the compliance question must be separated from the legal-permissibility question. A transaction can be fully compliant with the Anti-Money Laundering and Counter-Terrorist Financing Ordinance and entirely outside any UN sanctions designation, and still face a banking-channel problem driven by the internal risk frameworks of correspondent institutions. Treating these as the same question – and expecting a permissibility analysis to resolve a banking-channel problem – is the most common error our desk sees in matters of this kind.
Second, the documentation must be structured for its actual audience. A legal opinion is not a compliance file. A compliance file is not a KYC pack. Each serves a different institutional reader. The bank's compliance unit needs a document that answers its questions in its own register: what is the relationship, who are the parties, what are the payments for, has the client screened the counterparty, and what is the sanctions position? Those questions have direct answers. The file should give them directly.
Third, timing matters. The compliance review should be completed before the contract is signed, not after the first payment is refused. Once a payment has been rejected or a relationship flagged internally at a bank, the review process is reactive rather than proactive, and the institutional trust the file needs to build starts from a lower base. The cost of a pre-contractual compliance review is almost always lower than the cost of remediation after a banking-channel failure.
For further context on the AML and source-of-funds considerations that arise in UAE counterparty relationships, see our related matter note on AML source-of-funds files for UAE counterparties and our briefing on sanctions due diligence in deals touching the CIS. Our full practice description is at Sanctions & AML.
Related practices
- Sanctions & AML – counterparty screening, compliance files, and sanctions-neutral contracting
- Corporate Counsel – ongoing governance and cross-border compliance for operating companies
Frequently asked questions
What does the route look like for a compliance review before contracting with the UAE entity?
What are the main risks in a compliance review before contracting with the UAE entity?
How long does a compliance review before contracting with the UAE entity usually take?
Speak with Lockhart & Yip
For a scoped view of your matter, contact info@lockhartyip.com. Discuss your matter →
Related
- Sanctions Aml
- Aml Source Funds File Uae Counterparty Uae Matter
- Sanctions Due Diligence Deal Touching Cis Cis Briefing
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@lockhartyip.com.