A compliance review before contracting with the UAE entity
A compliance review before contracting with the UAE entity. How Lockhart & Yip advises foreign principals on the route. Write to info@lockhartyip.com.
A cross-border contract with a UAE entity can stall, or worse, trigger a bank refusal, long after the commercial terms are agreed. The problem almost never sits in the commercial documents. It sits in the compliance file – and in whether that file was assembled before the contract was signed, or after the payment was blocked.
A compliance review before contracting with a UAE entity is a structured pre-transaction assessment of counterparty risk, sanctions exposure and source-of-funds positioning under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance and Hong Kong's United Nations sanctions obligations, designed to ensure that the payment channel remains open and that the contracting party owns a documented compliance position before any funds move.
This note sets out when that review is needed, the route we run, the cross-border interface between Hong Kong and the UAE, and the decisions the principal must own at each stage.
Why the trigger is almost always the bank, not the regulator
Most principals approaching us have already signed a term sheet. A correspondent bank – or their own relationship bank in Hong Kong – has flagged the counterparty or the jurisdiction, and the transaction is stalled at the payment stage.
That sequence is the wrong order. By the time a payment is blocked, the commercial commitment already exists. The compliance file is being built under pressure, often to a deadline the client did not set. The bank's request arrives first; the legal analysis follows, rather than leads.
In our cross-border practice, we regularly advise groups on reversing that sequence. The review runs before the contract is executed. The file is ready when the bank asks, because it was prepared for that purpose. That is the practical logic behind a pre-contracting compliance review, and it is the reason the trigger is overwhelmingly enforcement risk rather than regulatory inquiry.
The UAE sits in a position that demands careful handling. Hong Kong implements United Nations sanctions and does not give domestic effect to the unilateral measures of other states. At the same time, a Hong Kong bank – particularly one with correspondent relationships in the United States or the European Union – will apply its own group-level risk appetite, which may extend well beyond UN measures. Understanding that distinction, and documenting the position against each layer, is the work.
What the governing instruments require, and what the banks add
The Anti-Money Laundering and Counter-Terrorist Financing Ordinance sets the statutory baseline in Hong Kong: customer due diligence, ongoing monitoring, and documentation of the basis on which a business relationship is accepted and maintained. Those obligations attach to financial institutions and designated non-financial businesses and professions (DNFBPs – a category that includes lawyers, accountants and certain other intermediaries). They also define the compliance standard against which a counterparty's own file is measured when it is presented to a bank.
The United Nations Sanctions Ordinance implements UN-mandated asset freezes and dealing prohibitions in Hong Kong. Where a UAE entity, its ownership chain, or its beneficial controllers appear on a UN-designated list, any transaction is prohibited. That check is mandatory and non-negotiable. It is also, ordinarily, the simpler part of the analysis.
The harder layer is the bank's own correspondent banking risk policy (the internal rules a bank applies to cross-border payment channels, often derived from the group's US or EU compliance programme). A Hong Kong bank with a USD correspondent may apply OFAC screening as a condition of processing USD payments. A bank with an EU parent may apply EU Council measures. These are not Hong Kong legal obligations; they are contractual and operational conditions of the payment infrastructure the client is using. Ignoring that layer produces the scenario described above: a clean Hong Kong legal position that the bank will not process.
A compliance review before contracting maps all three layers – UN obligations, the Anti-Money Laundering and Counter-Terrorist Financing Ordinance standard, and the client's likely bank risk appetite – against the specific counterparty, the transaction structure and the payment route.
The sequence above describes the standard position. Your matter turns on the specific entity, its ownership structure, the sector, and the payment channel your bank actually uses – which is where the route is won or lost.
To discuss how these three layers apply to your counterparty and the transaction you are planning, contact info@lockhartyip.com.
How is the cross-border interface between Hong Kong and the UAE structured?
The Hong Kong – UAE axis is one of the most active cross-border commercial corridors in our practice, and it is one where the compliance architecture on each side has evolved significantly.
The UAE operates its own national sanctions regime, administered through the Executive Office for Control and Non-Proliferation (the UAE body responsible for implementing UN-mandated and domestic UAE sanctions designations) and its financial regulators, including the Central Bank of the UAE and the Dubai Financial Services Authority (DFSA – the regulator for the Dubai International Financial Centre, a common seat for UAE-based financial counterparties). The UAE has committed to Financial Action Task Force standards and has made significant legislative changes in recent years to address prior FATF findings.
A Hong Kong principal contracting with a UAE entity therefore sits at the intersection of two distinct regulatory architectures. The Hong Kong side requires a compliant customer due diligence file and clean UN screening. The UAE side requires the counterparty to demonstrate its own compliance position in a form that the UAE financial system, and any UAE bank in the payment chain, will accept. Neither side automatically satisfies the other.
Where the contract involves a payment through the UAE banking system – for example, a UAE entity paying a Hong Kong entity through a UAE correspondent – the UAE bank's own AML procedures apply to the Hong Kong recipient. Conversely, where the payment runs through the Hong Kong banking system to a UAE payee, the Hong Kong bank's risk appetite applies to the UAE counterparty. The practical implication is that the compliance file must be constructed for both ends of the transaction simultaneously.
In our cross-border practice, we structure the review to produce a file that addresses both regimes. Where UAE-law questions arise – licensing, beneficial ownership registers under UAE law, or the DIFC's own regulatory requirements – we coordinate with allied counsel admitted in the relevant jurisdiction. That coordination is built into the engagement from the outset, not added after the bank asks.
The route we run: step by step
The review follows a defined sequence. Each step produces a documented output that the client owns and can present to their bank, their auditors, or a regulator on demand.
Step 1: Entity mapping. We identify the UAE entity, its jurisdiction of incorporation (mainland UAE, ADGM, DIFC, or a free zone), its registered beneficial ownership and its corporate hierarchy. Where the entity sits within a wider group, we map the group to the level required by the client's bank risk policy. This step often surfaces issues that were not visible at the term-sheet stage – intermediate holding entities in third jurisdictions, nominee arrangements, or ownership chains that pass through sanctioned jurisdictions.
Step 2: Screening. We screen all identified entities and natural persons against UN consolidated lists and, where the client's bank requires it, against the additional designations that apply to the payment channel in use. We document the result. Where a hit is found, we stop and advise on the legal position before the review continues. Where a false positive requires resolution, we document the basis for clearance.
Step 3: Source-of-funds and source-of-wealth assessment. For a transaction above a certain scale, or where the counterparty's business model or ownership raises questions, we assess the source of funds entering the transaction and – where the individual controllers are relevant – the source of wealth of the beneficial owners. This is the area where banks most frequently push back. A file that addresses source of funds only at the entity level, without tracing the economic logic of the counterparty's business, will not satisfy a thorough correspondent bank review.
Step 4: Contractual structuring. We review the proposed contract documents for provisions that create additional compliance exposure: payment routes that route through third-jurisdiction entities, representations that the client cannot verify, or termination provisions that may produce a prohibited dealing if a subsequent designation occurs. Where revisions are needed, we advise on the form and coordinate with the client's commercial counsel.
Step 5: File assembly and bank communication. We assemble the compliance file in the format most likely to satisfy the client's bank. Where the bank has already issued a request for information, we structure the response to address each element of that request directly. Where the bank relationship is not yet stressed, we prepare the file as a proactive submission – sent before the first payment, so the bank's own compliance team has reviewed and accepted the counterparty before any transaction is processed.
Locally licensed Hong Kong firms join the engagement where a matter of Hong Kong law arises – for example, a specific question under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance as applied to a Hong Kong-incorporated entity, or a regulatory query from a Hong Kong-licensed institution. That coordination is part of our standard model for matters of this kind.
What the bank's request actually means – and what it does not
A bank's source-of-funds request is not a legal proceeding. It is an information demand from a counterparty in a commercial relationship, governed by the terms of the account agreement and the bank's own AML policy. That distinction matters for two reasons.
First, the standard of response is commercial, not forensic. The bank is not asking for proof beyond reasonable doubt that funds are clean. It is asking for a documented, reasonable basis on which it can record that it has conducted enhanced due diligence and reached a risk-acceptance decision. A well-constructed file achieves that standard. An over-engineered response – or one that is produced in an adversarial tone – can create exactly the impression of evasion it was intended to dispel.
Second, a bank refusal is not a final determination of legal liability. A bank may decline a transaction for reasons of risk appetite that have nothing to do with the legal position of the client. That distinction is important where a client is considering their options after a refusal. A refusal to process a payment is not a finding that the client has committed a sanctions offence or an AML breach. But it does require a decision: restructure the payment channel, provide additional documentation, or accept that this particular bank will not serve this particular transaction.
We regularly advise on all three outcomes. The compliance file built in the pre-contracting review is the foundation for whichever route is taken.
If an earlier filing or enforcement attempt produced an adverse or stalled result, a second read can identify the strategic error and the routes still open. Write to info@lockhartyip.com.
The documents and decisions the client must own
A compliance review produces outputs. Those outputs belong to the client. The client must understand what they are, why they were prepared, and how they will be used.
The core documents are: a counterparty risk assessment memorandum, setting out the entity mapping, screening results and basis for risk acceptance; a source-of-funds summary, appropriate to the transaction size and structure; a contractual review note, identifying and resolving compliance-relevant provisions in the transaction documents; and the assembled compliance file in the format required for bank submission.
The decisions the client must own are equally important. A compliance review does not outsource the principal's risk-acceptance decision to their advisers. The client decides whether to proceed with the counterparty on the basis of the information assembled. The client decides which payment channel to use. The client decides the level of ongoing monitoring appropriate to the relationship. Those decisions are recorded in the file, with the client as the named decision-maker. That is how the file functions as a defence document if a question later arises.
Clients who treat the compliance review as a box-ticking exercise – a document produced to satisfy the bank rather than a genuine assessment of the risk – are exposed in a way that a well-constructed file is not. The distinction between a compliance exercise and a compliance record is the difference between a document that satisfies the bank and a document that satisfies a regulator.
Common positions that weaken the compliance file
In our cross-border practice, we see a consistent set of file weaknesses that produce bank refusals or, in more serious cases, regulatory enquiries.
The first is incomplete beneficial ownership tracing. A file that identifies the UAE entity but stops at the first layer of corporate ownership does not satisfy enhanced due diligence standards for a complex transaction. The bank will ask for the ultimate beneficial owner – the natural person or persons who ultimately own or control the entity. If that information was not collected at the outset, collecting it under bank pressure is slower, more difficult, and more likely to produce gaps.
The second is a source-of-funds narrative that is asserted rather than evidenced. A statement that "the counterparty's funds originate from legitimate business operations in the UAE" is not a source-of-funds assessment. A file that links the counterparty's documented revenue streams, their sector activity, their banking history and their corporate structure to the specific funds entering the transaction is. The difference is the level of detail, and that detail takes time to assemble before it takes scrutiny.
The third is a payment structure that creates unnecessary complexity. Routing a payment through an intermediate entity in a third jurisdiction, or splitting a payment across multiple accounts, increases the bank's risk concern rather than reducing it. A clean payment structure – direct, documented, and consistent with the counterparty's declared business model – is always preferable from a compliance perspective, even where the commercial rationale for a more complex structure exists.
The fourth is a failure to consider the contractual risk of a subsequent designation. If a UAE counterparty is designated after the contract is signed but before performance is complete, the contract creates a prohibited dealing risk. A well-drafted contract contains provisions that address that scenario: termination rights, payment-hold mechanics, and representation obligations on the counterparty to notify of changes in ownership or regulatory status. Those provisions are compliance infrastructure, not commercial concessions.
Decision matrix: situation, instrument, route and risk
Different contracting scenarios with UAE entities produce different compliance routes. The following captures the material distinctions our desk sees in practice.
Situation A: A Hong Kong trading entity contracting with a UAE free-zone entity for a straightforward goods purchase, payment in USD through a Hong Kong correspondent bank. The instrument in play is the Anti-Money Laundering and Counter-Terrorist Financing Ordinance customer due diligence standard and UN screening. The route is a standard counterparty review with entity mapping and screening. The timing is short. The risk is low if the counterparty has clean ownership and the payment route is direct. The residual risk is correspondent bank OFAC screening, which applies to the USD payment regardless of the Hong Kong legal position.
Situation B: A Hong Kong holding entity entering a joint venture with a UAE family office-owned entity, with capital contributions flowing in both directions. The instrument is enhanced due diligence under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance, given the value and the ongoing nature of the relationship. The route requires beneficial ownership tracing to the family level, source-of-wealth assessment for the family principals, and contractual provisions addressing post-signing designation risk. The timing is longer. The risk is elevated by the ongoing relationship and the family-office structure, which typically involves multiple jurisdictions of incorporation and multiple layers of trusts or holding entities.
Situation C: A Hong Kong professional-services firm onboarding a UAE entity as a client, where the engagement itself involves managing the entity's funds or executing transactions on its behalf. Here the Firm is itself subject to designated non-financial business and profession obligations under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance. The route is a full client onboarding review, with enhanced due diligence and ongoing monitoring built into the engagement terms. The risk is regulatory and reputational: a failure to conduct the review adequately is a breach of the firm's own statutory obligations, not merely a commercial risk.
What foreign principals misread about the Hong Kong position
A persistent misconception among non-Hong Kong principals is that Hong Kong's sanctions regime is broadly permissive because it does not give domestic effect to US or EU unilateral measures. That reading is correct as a statement of the legal position. It is incorrect as a guide to the practical operating environment.
A Hong Kong entity that transacts through the USD payment system is, as a matter of operational fact, subject to OFAC screening on every USD transaction. That screening is applied by the correspondent bank, not by a Hong Kong regulator. The consequences of a blocked transaction include payment failure, potential designation enquiry by the US Treasury's Office of Foreign Assets Control, and reputational damage to the relationship with the correspondent. None of those consequences require a Hong Kong regulatory breach to materialise.
Similarly, a Hong Kong entity that is majority-owned by a EU-headquartered parent group may be subject to EU Council measures as a matter of the parent group's group-level compliance policy, even where the Hong Kong entity itself has no EU regulatory exposure. That group-level overlay is not a matter of Hong Kong law; it is a matter of the corporate governance of the group. But it defines the actual operating space of the Hong Kong entity.
Understanding the difference between the Hong Kong legal position and the practical payment-system position is one of the most important services we provide to foreign principals entering a cross-border transaction with UAE counterparties. The legal analysis is the foundation. The payment-channel analysis is the architecture that determines whether the transaction actually completes.
For a structured assessment of your counterparty position and payment channel across Hong Kong and the UAE, write to us at info@lockhartyip.com.
Related practices
- Sanctions & AML – cross-border compliance advisory, counterparty review and source-of-funds positioning
- Responding to a bank's source-of-funds request – managing and resolving bank information demands on cross-border transactions
Frequently asked questions
How long does a compliance review before contracting with the UAE entity usually take?
What are the main risks in a compliance review before contracting with the UAE entity?
What documents are needed for a compliance review before contracting with the UAE entity?
Speak with Lockhart & Yip
For a scoped view of your matter, contact info@lockhartyip.com. Discuss your matter →
Related
- Sanctions Aml
- Responding Bank S Source Funds Request
- Aml Source Funds File Cis Counterparty Cis Briefing
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@lockhartyip.com.