Compliance & Risk

KYB, UBO and AML Checks for UAE Vendors Explained

KYB, UBO and AML are three acronyms that get used almost interchangeably in procurement conversations, which is unfortunate because they mean genuinely different things and require different evidence. Getting them conflated is how vendor files end up with a licence copy standing in for an ownership check, or a sanctions screen standing in for both. This article separates the three, explains what each actually verifies, and walks through the UAE-specific detail — particularly the 25% ownership test and which sanctions lists genuinely apply — that most generic guides skip.

What Is Know Your Business Verification?

KYB verifies that an organization exists, is active, operates under its claimed identity, and is authorized for the business activity you're actually contracting it for. It typically covers registry and licence data, legal form, addresses, activities, ownership, management, tax status, and any adverse or regulatory information on record. KYB is the business counterpart of KYC (Know Your Customer), but how deep it needs to go depends on your organization's own legal obligations and the specific vendor's risk profile — not a fixed universal depth.

What Is Ultimate Beneficial Ownership?

A UBO is the natural person who ultimately owns or exercises effective control over a legal entity, including through indirect ownership or other means of control. Critically, this is not necessarily the named manager, the legal representative on the licence, or the immediate corporate shareholder listed on a registry extract — those are often just the visible layer. UBO identification exists to reveal hidden control, conflicts of interest, sanctions exposure, and ownership structures deliberately built to obscure accountability.

Who Qualifies as a UBO in the UAE?

Under Cabinet Resolution No. 109 of 2023, the starting test is a natural person who ultimately owns or controls 25% or more, directly or indirectly, including through voting rights. If no natural person is identified under that ownership test, control through other means is considered next. If still no one can be identified through ownership or control, the relevant senior-management official may be treated as the beneficial owner under the fallback provision. Apply exemptions and special regimes carefully — mainland companies, free-zone entities, listed companies and government-related entities don't all follow the same evidence route, so don't assume one approach transfers cleanly across all of them.

Which Business Documents Are Required for KYB?

How to Verify a Vendor's Ownership Structure

Reconcile the ownership chart against official documents at every layer — the percentages should actually total correctly, which sounds obvious but is a surprisingly common failure point. For foreign corporate shareholders, obtain current registry extracts from their home jurisdiction along with reliable translations where required. Identify indirect holdings by multiplying ownership percentages across layers, while separately examining control rights that don't necessarily follow equity — voting agreements, trusts, nominee arrangements, and powers to appoint management can all confer control without a matching equity stake. Record gaps explicitly and require remediation, rather than quietly converting an unverified vendor declaration into a "verified" UBO result because the deadline is close.

Which Vendor Stakeholders Should Be Screened?

At minimum: the vendor entity itself, including trading names and former names. Beyond that, UBOs and controlling owners, and directors, senior managers and authorized signatories according to risk and any applicable rules your organization is subject to. Where they create material exposure, extend screening to relevant parent companies, affiliates, agents, intermediaries and subcontractors. The discipline worth holding onto here: screen only who's necessary, use lawful data sources, and avoid retaining more personal information than the purpose actually requires.

Sanctions, PEP and Adverse-Media Screening

Sanctions screening checks whether a person or entity matches an applicable prohibition or restriction. PEP screening identifies political exposure and associated corruption risk — a match calls for risk-based enhanced review, and doesn't by itself establish wrongdoing. Adverse-media review assesses credible reporting on fraud, corruption, sanctions evasion, financial crime, or serious safety, labour or environmental misconduct. In every case, resolve potential matches using multiple identifiers — not name alone — and record explicitly whether the result is confirmed, a false positive, a possible match, or inconclusive. Our detailed walkthroughs of AML and sanctions screening and adverse-media screening specifically go deeper into building this into an onboarding workflow without stalling procurement.

UAE and International Sanctions Lists

The core official UAE targeted-financial-sanctions sources are the UAE Local Terrorist List and the UN Security Council Consolidated List, published via the UAE Executive Office. Regulated entities must follow the applicable Executive Office and regulator rules — including the Central Bank of the UAE's targeted financial sanctions requirements for the banking sector — on list updates, screening frequency, freezing or suspension, and reporting. Other lists, such as OFAC, UK, EU, or additional national regimes, may become relevant because of the buyer's own location, currencies, banks, counterparties or contract structure — but they're not interchangeable with the UAE's own lists, and the specific list universe your organization screens against should be defined explicitly in policy, with timestamped evidence of the lists and configuration actually used.

Common KYB and UBO Red Flags

When Should Vendors Be Rescreened?

At onboarding and before activation, where policy or applicable regulation requires it. On every official sanctions-list update for entities subject to continuous TFS obligations, with a proportionate periodic schedule for organizations that aren't. Whenever ownership, management, legal name, country, bank account, or contract scope changes. Whenever adverse information, enforcement action, a suspicious transaction, or another risk event surfaces. And periodically according to risk more broadly — more frequently for critical, high-risk or regulated relationships than for a low-value, easily replaced supplier.

Automating KYB, UBO and AML Checks

Vendoreye extracts legal entities, shareholders and control relationships directly from submitted evidence and visualizes the resulting ownership chain, rather than leaving a reviewer to reconstruct it from separate PDFs by hand. Registry and licence fields get matched automatically, inconsistencies get detected, and foreign or complex ownership structures are routed for enhanced review instead of getting waved through under deadline pressure. Configured entities and stakeholders are screened automatically, with false positives managed and every list, date, result and reviewer rationale preserved against the vendor's record. Rescreening triggers on risk events or a defined schedule, and the platform prevents silent approval when evidence is genuinely incomplete — see how this connects to the broader UAE vendor onboarding workflow. A human decision-maker stays firmly in the loop for ambiguous matches, PEP risk, adverse-media interpretation and exceptions — this is deliberately a control and evidence layer, not an automated approval engine.

This article is for general informational purposes and does not constitute legal advice. It reflects an editorial research summary, not a review by UAE counsel. Requirements vary by sector, emirate, free zone, licence and contract, and laws and official guidance change. Verify current requirements against the official sources cited and consult qualified counsel before relying on this content for compliance decisions.
KYBBeneficial OwnershipAMLSanctions ScreeningGCC Compliance

Frequently Asked Questions

What is the difference between KYB and KYC?

KYB (Know Your Business) verifies that an organization exists, is active, operates under its claimed identity, and is authorized for its intended activity. KYC (Know Your Customer) is the equivalent process applied to individuals. KYB is effectively the business counterpart of KYC, though the required depth of either depends on the buyer's legal obligations and the counterparty's risk profile.

What official sanctions lists apply in the UAE?

The core official targeted-financial-sanctions sources in the UAE are the UAE Local Terrorist List and the UN Security Council Consolidated List. Other lists such as OFAC, UK, or EU regimes may become relevant depending on the buyer's location, currencies, banks, counterparties or contract terms, but they are not interchangeable with the UAE's own lists and shouldn't be assumed to apply automatically.

Does a PEP match mean a vendor should be rejected?

No. PEP (politically exposed person) status is a risk factor that calls for enhanced, risk-based review — it does not by itself establish wrongdoing or justify automatic rejection. The right response is proportionate scrutiny, not an automatic block.

See how Vendoreye handles this in practice

Book a walkthrough of vendor intake, onboarding, screening and governance in one platform.

Action completed successfully.