UAE e-KYC Platform
Article

UAE e-KYC Platform: What It Means for AML Compliance in the UAE

Tatiana Rassokha Compliance Officer
8 October, 2026 18 min

Every visit to the UAE brings something new: a new skyscraper, a new district, another attraction in a country already full of remarkable places.

Regulation can leave the same impression if you are new to the UAE financial landscape, or have not followed it for some time.

For this visit, the Compliance Traveller takes a closer look at one of these changes: the UAE e-KYC platform.

The UAE e-KYC platform is the nationwide Know Your Customer system, created by Federal Decree-Law No. 30 of 2024 and operated by the Financial Identity Company under Central Bank supervision, that lets authorised financial institutions obtain consent-based KYC Reports from approved data sources. For AML compliance in the UAE, it changes where customer data comes from, not who is responsible for the decision.

Why the UAE Is Rethinking KYC

The UAE has spent years building a financial system that is faster, more digital and more connected to government data. Banking, payments and customer onboarding have all moved in that direction. KYC remains one of the harder parts of AML compliance in the UAE to modernise because the same customer information is still collected, checked and stored repeatedly across different institutions.

A UAE resident who opens a second bank account hands over the same Emirates ID, passport, address and employer details that the first bank already holds. A company does the same with its trade licence, constitutional documents and beneficial owners. Each financial institution checks the file and keeps its own record.

The underlying information changes over time.

The UAE has good reason to care about the quality of those records. FATF’s 2020 mutual evaluation described the country as a major global financial centre and trading hub exposed to significant money-laundering risks, and identified the misuse of legal persons as a real concern.

The same features that have helped the UAE attract international companies, investment and capital make customer identification more demanding. Financial institutions need to know who is behind a company, whether beneficial ownership has changed, where money comes from and whether information collected at onboarding remains reliable months or years later.

FATF scrutiny became more visible in March 2022 when the UAE entered increased monitoring. The following two years brought stronger supervision, more attention to beneficial ownership, greater use of financial intelligence and increased enforcement across financial institutions and other regulated sectors. In February 2024, FATF removed the UAE from increased monitoring after the country completed its action plan.

The UAE e-KYC platform followed later that year.

Federal Decree-Law No. 30 of 2024 created the legal basis for the “Know Your Customer” Digital Platform and for a dedicated company to operate it. The platform can receive KYC data from approved providers, including government authorities and financial institutions, and make KYC Reports available to authorised users under the conditions set by the law.

So which familiar problem is the platform intended to resolve? Banks and other financial institutions often end up asking customers for the same information, even when that information has already been collected and verified in another institution. The UAE e-KYC platform is designed to reduce that duplication and give institutions access to more consistent KYC and KYB information with the customer’s consent.

Much of the operating detail arrived in 2026. In April, the Central Bank of the UAE announced Norbloc AB as technology partner for the nationwide platform. The same month, the Cabinet issued the Executive Regulations under Cabinet Resolution No. 55 of 2026 and the administrative sanctions framework under Cabinet Resolution No. 56 of 2026. In June, the Cabinet approved the articles of association of the Financial Identity Company, owned jointly by the Federal Government, banks, insurance companies and exchange houses.

The Executive Regulations show how detailed the record can become. For an individual, the prescribed information can include Emirates ID, passport and residency details, address, employment information, principal sources of income and PEP information. For a company, it can include licensing information, senior management, beneficial owners and tax information.

Fraud adds another reason to improve the quality of onboarding data. Stolen identities, altered documents and synthetic identities often exploit weak or inconsistent information. Mule accounts can begin with the same weakness. When institutions hold different versions of the same customer record, those gaps can make fraud and financial crime harder to identify. A regulated source gives institutions a more consistent starting point.

A genuine Emirates ID record does not prove that the person holding the phone is the genuine customer. A correct company record does not tell a bank whether tomorrow’s transaction makes sense, a limit that money-laundering cases built on forged documents have already exposed.

The bank still has to verify identity, understand the customer, identify beneficial owners where required, screen for sanctions and PEPs, assess risk and monitor the relationship. Those responsibilities remain with the financial institution under the UAE’s AML law, Federal Decree-Law No. 10 of 2025.

The UAE e-KYC platform changes the information available for those decisions and the way that information can be obtained, updated and shared. The compliance decision remains with the financial institution.

That leaves some practical questions. Is the platform mandatory for banks and other financial institutions? What does a KYC Report cost? How much reliance can be placed on one? Who corrects information when it is wrong or outdated? And what happens to the KYC and identity-verification systems banks already use?

To answer those questions, it helps first to understand how the platform is designed to work.

What Is the UAE e-KYC Platform?

The UAE e-KYC platform gives financial institutions a regulated way to obtain Know Your Customer and Know Your Business information from organisations that already hold and maintain that data.

The basic flow is simple. A bank obtains the customer’s consent, requests a KYC Report and states why it needs the information. The platform gathers the relevant data from approved providers and returns the report to the bank.

Three legal instruments govern the process. Federal Decree-Law No. 30 of 2024 created the platform. Cabinet Resolution No. 55 of 2026 explains how KYC data and reports are requested, issued, used, corrected, protected and retained. Cabinet Resolution No. 56 of 2026 sets the administrative fines for breaches.

The Central Bank describes the project as a nationwide unified platform for individuals and businesses. Its purpose is practical: reduce repeated customer checks, automate parts of KYC and KYB, and allow verified information to move securely between approved sources and authorised institutions with the customer’s consent, the same principle behind the UAE’s Open Finance framework.

Who is involved?

Four parties make the system work. The Financial Identity Company operates the platform. Data providers supply KYC information and can include government bodies, private companies, financial institutions, insurers and other approved organisations. The customer is the individual or legal person described in the report, and consent is normally required before a report is requested. The user is the institution entitled to obtain the report for its due-diligence obligations.

The same organisation can have more than one role. A bank, for example, may provide customer data to the platform and request KYC Reports when carrying out its own due diligence.

Who operates the platform?

The Financial Identity Company operates the UAE e-KYC platform under the supervision of the Central Bank of the UAE. It manages the platform, enters into agreements with data providers and issues KYC Reports. The Central Bank sets the relevant controls, determines which customer information may be requested and can issue Codes of Conduct for providers and users.

Responsibility for the data is divided as well. A provider checks that the information it supplies is valid, accurate and current and corrects its source record when necessary. The Financial Identity Company produces the report from the information supplied. The user keeps the report confidential and uses it for the purpose stated in the request.

How does it work?

Return to the UAE resident opening a second bank account. The bank asks for consent, explains why the report is needed and submits the request with the customer’s identifying details, the stated purpose and evidence of consent.

The Financial Identity Company processes the request, obtains the relevant information from its data providers and makes the KYC Report available once the prescribed fee has been paid. The bank then uses the report alongside the other checks required for the customer, the product and the level of risk. The decision to open the account, and the risk rating applied, remain with the bank.

Customers can request access to their own KYC Report and ask for inaccurate or outdated information to be corrected.

What information can the report contain?

For an individual, the report can include identity and residency details, address, occupation and employer, contact details, principal sources of income and PEP information. For a company or other legal person, it can include licensing and registration information, senior management, beneficial owners, capital, sources of funding and income, share information and tax registration details.

A financial institution acting as a data provider can also supply customer information it already collects under Central Bank requirements. The information needed for a particular relationship will still depend on the customer, the product and the level of risk.

How is it different from the UAE PASS?

UAE PASS is the UAE’s national digital identity. It helps individuals authenticate when accessing government and private-sector services, sign documents and share official documents. The e-KYC platform serves a different purpose: it gives an authorised institution a KYC Report assembled from approved data providers for customer due diligence.

The two can work together. A customer can use UAE PASS to authenticate when entering a bank’s digital service, while the bank uses the e-KYC platform to obtain the customer information needed for the KYC file. UAE PASS helps establish the digital identity used in the interaction; the e-KYC platform provides the underlying customer record.

With the model defined, the next question is where implementation stands today.

UAE e-KYC Platform: Current Implementation Status

Two years after the law was introduced, the UAE e-KYC platform is beginning to take a more visible shape. The rules now explain how information will move through the system, the Financial Identity Company has been created to run it, and the technical work is moving forward under the Central Bank’s programme.

What is already in place?

Federal Decree-Law No. 30 of 2024 has been in force since October 2024. The Executive Regulations followed in April 2026 and provided the operating detail needed for KYC Reports, customer consent, corrections, data responsibilities and use of the platform.

The framework also carries real consequences. Unauthorised disclosure of KYC data and access to a KYC Report without the required approval can amount to criminal offences under the decree. Cabinet Resolution No. 56 of 2026 added administrative fines of AED 50,000 or AED 100,000 for most of the listed breaches.

The technical build is under way as part of the Central Bank’s Financial Infrastructure Transformation programme. The Central Bank has also indicated that later phases will broaden the platform’s capabilities and connect additional stakeholders.

Who owns the Financial Identity Company?

The company was formalised in June 2026 through Cabinet Resolution No. 102 of 2026. It is based in Abu Dhabi and has capital of AED 120 million.

The Federal Government owns 20%. Banks collectively own 60%, insurance companies 10% and exchange houses 10%. The shareholder list includes 13 banks, seven insurers and four exchange houses. First Abu Dhabi Bank, Emirates NBD and Abu Dhabi Commercial Bank hold the largest bank stakes.

That shareholder base matters because many of the same institutions will contribute data and request reports.

Financial institutions and insurance companies acting as data providers supply information requested by the Financial Identity Company under agreements based on a Central Bank template, at no cost to the company.

What still needs to be published?

Several pieces of information are still needed for full technical planning.

The first is pricing. The Central Bank’s Board of Directors sets the fee for a KYC Report following a proposal from the Financial Identity Company. A public tariff has yet to be issued.

The Codes of Conduct for data providers and users are another important piece. The decree gives the Central Bank authority to issue them, and the Executive Regulations refer to them throughout the framework.

Institutions will also need the technical connection requirements: interfaces, implementation sequence, onboarding procedures and the timetable for different categories of participants. Those details will determine the amount of work required inside each institution.

Is the UAE e-KYC platform mandatory for banks?

As of October 2026, connection deadlines for banks remain a matter for the Central Bank’s controls.

Federal Decree-Law No. 30 of 2024 and the Executive Regulations establish the rules for participation and give the Central Bank authority to issue binding controls. A sector-wide connection requirement can therefore be introduced through those controls.

Banks are already part of the framework in other ways. They appear as data providers and many are shareholders in the Financial Identity Company.

What can institutions prepare now?

There is already enough information for compliance and technology teams to begin preparing.

The required KYC data fields are published. The consent rules are known. Responsibilities for data accuracy, customer access and corrections are defined.

A bank can compare those requirements with its existing customer records and onboarding process. It can identify which information may eventually come from the national platform, which checks remain internal and how differences between records should be handled. It can also decide where a KYC Report enters the customer journey.

That work matters for periodic review as much as onboarding. Customer information changes over time: shareholders, beneficial owners, employers, addresses, residency status and PEP classification can all change. A fresh KYC Report gives the institution access to the current information held by the relevant data providers at the time of the request.

The next implementation challenge happens inside each institution: connecting the national report to existing onboarding, periodic review, screening and customer-risk processes. Those decisions now have to be made against a wider set of AML and KYC changes introduced in the UAE in 2025 and 2026.

Recent UAE AML and KYC Changes: What Has Changed?

The e-KYC platform arrived while the UAE was also rewriting its wider AML framework. Federal Decree-Law No. 10 of 2025 replaced the previous AML law in October 2025, followed by Cabinet Resolution No. 134 of 2025. Enforcement remained active. In May 2025, the Central Bank fined one exchange house AED 200 million after examinations found significant failures in its AML framework.

Two further Central Bank regulations took effect in September 2026 and shape how banks will operate the UAE e-KYC platform. One focuses on operational resilience. The other adds customer-data protections for SME banking. Both affect the systems, vendors and controls around KYC.

What happens if the KYC service goes down?

The Central Bank’s Operational Risk Management Regulation C 1/2026 took effect on 14 September 2026. Where onboarding, identity verification or access to the UAE e-KYC platform becomes a critical dependency, the institution has to include that dependency in its operational-risk and resilience planning.

That becomes very practical during an outage. A bank needs to know whether onboarding can continue, when a manual fallback is appropriate, which records must be preserved and how information is reconciled once the service returns. The same thinking applies to an external identity or screening provider that supports the customer journey.

The regulation also sets short notification periods for specified incidents: four hours for events that significantly affect, or may significantly affect, Critical Operations; 24 hours for a summary report; and 72 hours for high-risk incidents. A serious interruption to KYC or identity services can therefore become a regulatory event as well as a technology problem.

What changes for SME customer data?

The SME Customer Protection Regulation C 2/2026 took effect on 13 September 2026. It applies to banks and finance companies serving SME customers and adds explicit requirements around customer-data protection. These include collecting only the information needed, monitoring access, keeping records securely for at least five years and escalating significant data breaches.

KYC and KYB files contain some of the most sensitive information a financial institution holds: identity documents, addresses, ownership structures, PEP information and financial details. Once a KYC Report enters that file, access to it needs the same discipline. Compliance teams need to know who can see the information, why it is being kept, how long it remains available and what happens if it is exposed or used incorrectly.

The platform rules already require KYC Reports and the data contained in them to remain in the UAE. The September customer-protection rules add a broader data-management layer for SME files. For institutions using regional support teams, global cloud services or shared analytics environments, that combination deserves attention during system design and vendor review.

What do the September changes mean for the platform?

Federal Decree-Law No. 30 of 2024 and the 2026 Executive Regulations continue to define the platform itself: the KYC Report, consent, data providers, users and correction process. The September regulations shape what happens around that framework once banks begin relying on it in everyday operations.

Connecting to the platform involves more than exchanging customer data. Banks also have to plan for service continuity, access control, incident handling, vendor dependencies and the evidence they may later need to produce for the Central Bank. Those controls will shape how the platform fits into existing onboarding and periodic-review processes.

UAE e-KYC platform and AML framework: key instruments at a glance

InstrumentDateWhat it covers
Federal Decree-Law No. 30 of 2024In force October 2024Creates the KYC Digital Platform and the company that operates it
Federal Decree-Law No. 10 of 2025October 2025UAE AML law; defines the institution’s AML responsibilities
Cabinet Resolution No. 55 of 2026April 2026Executive Regulations: KYC Reports, consent, corrections, data responsibilities
Cabinet Resolution No. 56 of 2026April 2026Administrative fines for breaches (AED 50,000 or AED 100,000 for most)
Cabinet Resolution No. 102 of 2026June 2026Articles of association of the Financial Identity Company
Operational Risk Management Regulation C 1/202614 September 2026Resilience planning and incident notification (4h / 24h / 72h)
SME Customer Protection Regulation C 2/202613 September 2026Customer-data protection for SME banking

What the UAE e-KYC Platform Means for Financial Institutions

The customer file is probably where banks will notice the change first. Information they collect separately today, such as Emirates ID details, address, employer and company ownership, can arrive through a KYC Report from approved data providers. That can reduce repeated collection and give the compliance team a clearer record of where the information came from.

How does the UAE e-KYC platform affect AML compliance?

Federal Decree-Law No. 10 of 2025 continues to define the bank’s AML responsibilities: verify identity, understand the customer, identify beneficial owners where required, screen for sanctions and PEPs, assess risk and monitor the relationship. The KYC Report strengthens the information used at onboarding and periodic review. Risk judgement and the final decision remain with the financial institution.

The report also brings its own handling rules. The bank records the customer’s consent, uses the report for the stated purpose, keeps it confidential, retains it for at least five years and keeps the report and its data inside the UAE. International groups that review customer files from regional or global hubs will need to design that workflow carefully.

How much reliance can a bank place on a KYC Report?

The value of the report comes from the source of the information. Data providers are responsible for checking that what they supply is valid, accurate and current. The report therefore gives the bank a regulated source for facts such as identity details, address, employer or company ownership.

The date still matters. People change jobs and addresses; companies change directors, shareholders and beneficial owners. When the platform record and the bank’s own file differ, the discrepancy becomes part of the review. The customer can request a correction, the provider can update its record and the bank documents the decision it makes.

Does the UAE e-KYC platform replace existing KYC systems?

The UAE e-KYC platform works alongside the KYC systems banks already use. Banks will continue to use onboarding systems, identity verification, biometrics, sanctions screening, risk scoring and transaction monitoring. The KYC Report becomes another input into those processes, with the advantage of drawing prescribed customer data from approved sources.

The KYC Report can provide reliable information about the customer record. The bank’s identity controls still have to establish that the person using the digital channel is the person connected to that record.

Conclusion: What Banks Can Prepare Now

Financial institutions already have enough information to begin preparing. Banks can map the published data fields and consent rules against their current customer records and decide where a KYC Report would enter onboarding and periodic review. The regulations in force since September 2026 add two items to that work: a fallback for the day the service is unavailable and clear control over who can see a KYC Report.

The fee, the Codes of Conduct and the technical connection requirements remain the main announcements to watch. They will determine the cost, sequencing and technical effort of implementation.

A UAE resident opening a second bank account today may still be asked for information another institution already holds. Once the new bank is connected, it can request a KYC Report with the customer’s consent and obtain that information from approved sources. For the customer, that should mean fewer repeated requests. For the compliance team, it means more time for the parts of KYC that require judgement.

The Compliance Traveller has already marked February 2027 in the calendar for another close look at the UAE, after FATF plenary discussion is completed.

Frequently Asked Questions About the UAE e-KYC Platform

The UAE e-KYC platform gives financial institutions a regulated way to obtain Know Your Customer and Know Your Business information from organisations that already hold and maintain that data. The Financial Identity Company operates the UAE e-KYC platform under the supervision of the Central Bank of the UAE.

As of October 2026, connection deadlines for banks remain a matter for the Central Bank’s controls. A sector-wide connection requirement can therefore be introduced through those controls.

UAE PASS is the UAE’s national digital identity. The e-KYC platform serves a different purpose: it gives an authorised institution a KYC Report assembled from approved data providers for customer due diligence.

The KYC Report strengthens the information used at onboarding and periodic review. Risk judgement and the final decision remain with the financial institution.

The UAE e-KYC platform works alongside the KYC systems banks already use. The KYC Report becomes another input into those processes, with the advantage of drawing prescribed customer data from approved sources.

Ready to protect your users?

Discover how Facephi's biometric technology can safeguard your identity verification process.

Facephi Facephi Identity Platform Onboarding Authentication UX Consultancy Facephi Builder Facephi Central Services Fraud Intelligence Platform Identity Fabric KYB Platform Teseo Identity Wallet IDV Suite Cuentas Mula Behavioural Biometrics Linkedin YouTube X Facebook
Secret Link