Last updated: 12 July 2026
Ongoing monitoring is where most UAE AML programmes quietly fall behind. Onboarding checks get done well, then the customer file sits untouched until something breaks. Under Federal Decree-Law No. 10 of 2025, keeping customer due diligence current is not optional, and the Central Bank of the UAE (CBUAE) has made clear that a stale risk profile is treated as a control failure. This guide sets out how a UAE firm builds a practical ongoing monitoring and periodic KYC review process: the review cadence by risk, the trigger events that force a mid-cycle review, the step-by-step review workflow, the governance sign-off, and the evidence a supervisor expects to see.
Quick Answer
Ongoing monitoring in UAE AML compliance means keeping each customer’s due diligence and risk rating current for the life of the relationship. Firms run scheduled KYC reviews by risk tier (high-risk roughly every six months, medium-risk annually, low-risk every two to three years) and trigger-based reviews when circumstances change, under Federal Decree-Law No. 10 of 2025 and the April 2026 CBUAE guidance.
Key Takeaways
- It is a legal duty, not a courtesy: Federal Decree-Law No. 10 of 2025 and Cabinet Decision No. 134 of 2025 require regulated firms to conduct ongoing due diligence and keep CDD records current.
- Cadence follows risk: high-risk customers are reviewed most often (about every six months, or quarterly for the highest tiers), medium-risk annually, low-risk every two to three years.
- Triggers override the schedule: ownership changes, new activity, unusual behaviour, and sanctions or PEP hits force a review before the next scheduled date.
- The 2026 shift is to dynamic reassessment: the 16 April 2026 CBUAE guidance moves firms from fixed periodic reviews toward continuous, risk-based reassessment across the customer lifecycle.
- Governance matters: review outcomes, especially risk-rating changes, need a documented sign-off and a clear escalation path to the MLRO.
- Penalties are real and personal: administrative fines run from AED 50,000 to AED 5,000,000 per violation, and CBUAE has fined an MLRO AED 300,000 personally for framework failures.
What is ongoing monitoring in UAE AML compliance?
Ongoing monitoring is the continuous process of scrutinising a customer relationship after onboarding to confirm that the activity, the documentation, and the assigned risk rating still match reality. It has two linked parts: watching transactions and behaviour for anomalies, and periodically refreshing the customer’s identity data and risk assessment (often called periodic KYC review or ongoing customer due diligence).
The point is simple. A customer you rated low-risk in 2024 may have added a high-risk trading line, changed beneficial owners, or started moving funds through a sanctioned corridor. Without a review process, your file still says low-risk, your controls stay light, and your firm is exposed. Ongoing monitoring closes that gap.
Ongoing monitoring vs transaction monitoring
These terms get used interchangeably, but they are not the same. Transaction monitoring is one input into ongoing monitoring, not the whole of it.
| Aspect | Transaction monitoring | Ongoing monitoring (ongoing CDD) |
|---|---|---|
| Focus | Individual transactions and patterns | The whole customer relationship and risk profile |
| Trigger | A rule, threshold, or alert fires | A schedule by risk tier, plus event triggers |
| Output | Alerts to investigate, possible STR | Refreshed KYC, updated risk rating, control changes |
| Time horizon | Real-time or near real-time | Periodic, with continuous reassessment overlay |
A mature programme runs both. Alerts from transaction monitoring feed the periodic review, and the review in turn recalibrates the thresholds and scenarios the monitoring system uses.
The legal basis in UAE law
The obligation sits directly in statute. Federal Decree-Law No. 10 of 2025 on Anti-Money Laundering, Combating the Financing of Terrorism and the Financing of Illegal Organisations came into force on 14 October 2025 and replaced the earlier Federal Decree-Law No. 20 of 2018. It requires regulated entities to conduct ongoing due diligence on the business relationship and to keep the documents, data, and information collected under CDD accurate and up to date.
Cabinet Decision No. 134 of 2025, the executive regulations effective 14 December 2025, sets out the operational detail, including the record-keeping obligation of at least five years. For designated non-financial businesses and professions (DNFBPs), the Ministry of Economy DNFBP Guidelines (September 2025) and the Implementation Guide on Customer Risk Assessment (November 2024) spell out the periodic customer-risk-reassessment expectation.
Need help mapping your regulatory obligations? ADZ’s compliance advisory team builds and reviews ongoing monitoring frameworks for CBUAE, DFSA, and VARA-regulated entities. Contact ADZ’s compliance advisory team.
The 2026 shift: from static reviews to dynamic reassessment
The most important change this year is a change in expectation. On 16 April 2026, CBUAE issued updated AML/CFT/CPF guidance that moves supervised firms away from static, fixed-interval reviews and toward continuous, technology-enabled, risk-based reassessment across the full customer lifecycle.
In plain terms: a periodic review calendar is still expected, but it is now the floor, not the ceiling. Firms are meant to reassess a customer’s risk as soon as new information appears, rather than waiting for the anniversary date. A sanctions-list update that matches a customer, a sudden change in transaction behaviour, or a new corporate structure should each pull that customer forward for review immediately.
This connects ongoing monitoring to the wider risk-based approach. The controls you apply to a customer should flow from the customer’s current risk rating, and that rating only stays accurate if the review process keeps it fresh. For the enterprise view that sits above individual customers, see our guide to the AML business risk assessment.
How often should you review KYC in the UAE?
There is no single fixed frequency in UAE law. The frequency is set by the customer’s risk rating, and the firm documents its own cadence in its AML policy. The market standard, reflected in UAE guidance and supervisor expectations, is a tiered schedule with event-driven reviews layered on top.
| Risk tier | Scheduled review cadence | Typical scope |
|---|---|---|
| High-risk (PEPs, sanctioned-jurisdiction links, complex ownership) | Every 6 months; quarterly for the highest tiers | Full KYC refresh, enhanced due diligence, source of funds review |
| Medium-risk | Annually | Verify key data, re-screen, confirm risk rating |
| Low-risk | Every 2 to 3 years | Confirm details unchanged, re-screen, document rationale |
| Any tier, on trigger | Immediately | Targeted review of the changed factor, then re-rate |
Two rules keep this defensible. First, set the cadence in writing and apply it consistently. Second, treat the schedule as a minimum: a high-risk review that is not due for four months still happens now if a trigger fires. High-risk relationships also call for enhanced due diligence at each review, not just at onboarding.
What triggers a KYC review in the UAE?
Trigger-based reviews are the part competitors tend to skip. A scheduled calendar catches slow drift. Triggers catch the sudden changes that create the real risk. Build an explicit trigger list into your policy so that front-line and compliance staff know exactly what pulls a customer forward.
- Ownership or control changes: a new ultimate beneficial owner, a change of directors, or a corporate restructuring.
- New activity or products: the customer starts a new business line, a new jurisdiction, or a product that carries higher risk.
- Transaction anomalies: volumes, values, or counterparties that do not fit the expected profile, flagged by transaction monitoring.
- Screening hits: a new sanctions, PEP, or adverse media match against the customer or a connected party.
- Negative news: credible reporting of financial crime, fraud, or regulatory action involving the customer.
- Document expiry: expired identification, licences, or trade documents that need renewal.
- Regulatory change: a new obligation or a supervisor request that affects a class of customers.
Each trigger should route to a named owner with a target turnaround. A sanctions hit needs same-day attention; an expired trade licence can follow a normal review queue. Re-screening at each review draws on your PEP screening and adverse media screening processes.
The periodic KYC review workflow, step by step
A review is only useful if it is a real reassessment, not a box-tick. Use a consistent workflow so every reviewer covers the same ground and the output is comparable across the book.
- Pull the case. Gather the current KYC file, the risk rating and its rationale, transaction history since the last review, and any open alerts.
- Re-verify identity and structure. Confirm the customer, the beneficial owners, and the control structure are unchanged, or capture what changed.
- Re-screen. Run fresh sanctions, PEP, and adverse media screening on the customer and connected parties.
- Assess activity. Compare actual transaction behaviour against the expected profile set at onboarding; investigate material deviations.
- Reassess source of funds and wealth for higher-risk customers, and refresh supporting evidence.
- Re-rate. Recalculate the risk rating using your methodology; record any change and the reason.
- Recalibrate controls. Adjust monitoring thresholds, review frequency, and due-diligence level to match the new rating.
- Sign off and document. Record the outcome, the evidence reviewed, the decision, and the approver, then set the next review date.
Where an activity assessment surfaces something suspicious, the reviewer does not resolve it inside the KYC file. It escalates for a suspicious transaction report. Our guide on how to file an STR through goAML sets out that path.
Manual reviews do not scale. First Compliance automates periodic-review scheduling, sanctions and PEP re-screening, and case documentation, drawing on 1,800+ sanction lists and 5.5M+ PEP records. See how First Compliance handles ongoing monitoring.
Governance, sign-off, and escalation
Supervisors look closely at who decided what, and on what basis. A review that lowers a customer from high to medium risk without a documented reason and an approver is a finding waiting to happen. Set clear roles so accountability is not ambiguous.
- Reviewer: performs the review, gathers evidence, proposes the risk rating.
- Compliance approver: checks the work and signs off routine outcomes.
- MLRO: approves high-risk decisions, rating downgrades on sensitive relationships, and any decision to exit or retain a flagged customer.
- Senior management: receives management information on review completion rates, overdue reviews, and risk-tier movement.
Escalation should be defined, not improvised. A confirmed sanctions match, a decision to keep a high-risk customer, or a suspicion of money laundering each has a named path to the MLRO and a recorded decision. The personal stakes are not hypothetical: in mid-2026 CBUAE imposed a personal penalty of AED 300,000 on a Head of Compliance and MLRO for failures in an AML framework, alongside an AED 20 million fine on the institution.
Documentation and evidence standard
If it is not written down, it did not happen. Every review needs an evidence trail that a supervisor or independent auditor can follow without asking you to explain it. At minimum, each review record should hold:
- The review date, the trigger (scheduled or event), and the next scheduled date.
- The documents and data checked, with versions or timestamps.
- The screening results and how any hits were resolved.
- The activity assessment and any investigation notes.
- The prior and new risk ratings, with the reason for any change.
- The control changes made as a result.
- The reviewer, the approver, and the date of sign-off.
Keep these records for at least five years in line with Cabinet Decision No. 134 of 2025. Clean, consistent records are also what turn an independent audit from a scramble into a routine exercise.
Ongoing monitoring and the wider AML programme
Ongoing monitoring is not a standalone control. It is the mechanism that keeps the rest of your programme accurate. When a review re-rates a customer, that new rating should ripple outward.
- Onboarding CDD: the baseline that ongoing monitoring keeps current. See our customer due diligence guide.
- Sanctions screening: re-run at every review and on every trigger. See our sanction screening guide.
- Enterprise risk: aggregate review findings feed the business-wide risk picture and the update of your AML policy.
- Reporting: suspicions surfaced during review flow into STR filing via goAML to the UAE Financial Intelligence Unit.
Preparing for a CBUAE or supervisor inspection
Inspectors test ongoing monitoring by sampling files and asking a short, hard set of questions. You can prepare by answering them yourself first.
- Is there a written review cadence tied to risk rating, and is it applied consistently?
- Can you show a defined trigger list and evidence that triggers were actioned?
- Are overdue reviews tracked, reported to senior management, and cleared?
- For a sample of high-risk customers, is there a full, dated, signed-off review on file?
- Where a rating changed, is the reason documented and the approver recorded?
- Do monitoring thresholds and due-diligence levels actually match the current rating?
An independent AML audit run before the supervisor arrives finds these gaps while you can still fix them.
Test your framework before a regulator does. ADZ conducts independent AML/CFT audits for CBUAE, DFSA, and VARA-regulated entities, covering ongoing monitoring, review cadence, and evidence quality. Book an independent AML audit with ADZ.
Common ongoing-monitoring failures and the penalties
The failures supervisors cite most often are also the most avoidable.
- Reviews overdue or not done: the schedule exists on paper but files sit unreviewed past their date.
- Reviews that never re-rate: the reviewer confirms details but never revisits the risk rating, so ratings never move even when activity clearly changed.
- No trigger process: the firm waits for anniversary dates and misses ownership changes and screening hits in between.
- Thin evidence: a tick in a system with nothing to show what was checked or why a rating held.
- Stale screening: customers are not re-screened against updated sanctions and PEP data.
These are not filing technicalities. Under the executive regulations, administrative penalties commonly run from AED 50,000 to AED 5,000,000 per violation, alongside warnings, restrictions, suspension, and licence action; certain court-imposed fines on legal persons reach AED 5 million to AED 100 million. CBUAE issued over AED 370 million in AML/CFT fines during 2025. With the FATF mutual evaluation cycle keeping UAE enforcement firm through 2026, a weak review process is an expensive gap to leave open.
Build the skills in-house. Compliance 360 offers 32 KHDA-approved AML/CFT training courses, including practical modules on ongoing due diligence and customer risk reassessment. Explore Compliance 360 training.
Frequently Asked Questions
What is ongoing monitoring in AML?
Ongoing monitoring is the continuous review of a customer relationship after onboarding to confirm that the activity, documentation, and risk rating remain accurate. It combines transaction and behaviour monitoring with periodic KYC refreshes, and it is a legal obligation under UAE Federal Decree-Law No. 10 of 2025.
How often should you review KYC in the UAE?
Frequency is set by risk. The common standard is high-risk customers reviewed about every six months (quarterly for the highest tiers), medium-risk annually, and low-risk every two to three years, with trigger-based reviews carried out immediately when circumstances change. Firms document their cadence in the AML policy.
What is the difference between ongoing monitoring and transaction monitoring?
Transaction monitoring watches individual transactions for anomalies and generates alerts. Ongoing monitoring is broader: it covers the whole customer relationship, including periodic KYC refresh, re-screening, and risk re-rating. Transaction monitoring is one input that feeds ongoing monitoring; it is not the whole of it.
What triggers a KYC review in the UAE?
Common triggers include a change in ownership or control, a new business line or jurisdiction, unusual transaction activity, a new sanctions, PEP, or adverse media hit, negative news, and expired documents. A trigger pulls the customer forward for review regardless of the next scheduled date.
Is ongoing due diligence a legal requirement in the UAE?
Yes. Federal Decree-Law No. 10 of 2025 and Cabinet Decision No. 134 of 2025 require regulated firms to conduct ongoing due diligence and keep CDD information current. The 16 April 2026 CBUAE guidance further expects continuous, risk-based reassessment across the customer lifecycle.
What records should a KYC review keep?
Each review should record the date and trigger, the documents and data checked, screening results and their resolution, the activity assessment, the prior and new risk ratings with reasons, any control changes, and the reviewer and approver. Keep these records for at least five years.
Can ongoing monitoring be automated?
Yes, and at scale it usually must be. Software can schedule reviews by risk tier, run automated sanctions and PEP re-screening, flag triggers, and hold the case documentation. Human judgement still owns risk re-rating, escalation, and the decision to file a suspicious transaction report.
Related Reading
- AML Business Risk Assessment in the UAE: 2026 Guide
- AML Transaction Monitoring in the UAE: 2026 Setup Guide
- Customer Due Diligence (CDD) in the UAE: The Complete Compliance Guide
- Enhanced Due Diligence (EDD) in UAE: Complete 2026 Guide
- PEP Screening in the UAE: A 2026 AML Compliance Guide
- Adverse Media Screening in the UAE: 2026 AML Guide
- How to File an STR in the UAE: 2026 goAML Reporting Guide
Keep your customer risk current
Ongoing monitoring is the difference between a compliance programme that looks right on the day it was built and one that stays right. Set a cadence by risk, define your triggers, run a real reassessment at each review, and keep the evidence. If you want a second set of eyes on your framework, ADZ combines UAE-based advisory, independent AML audit, First Compliance software, and Compliance 360 training to keep customer risk accurate and inspection-ready. Contact ADZ for a consultation and gap analysis.
Outbound references: Central Bank of the UAE, FATF, UAE Ministry of Economy, UAE Legislation Portal.
Disclaimer: This article is general information on UAE AML/CFT compliance and is not legal advice. Obligations depend on your sector, licence, and supervisor. Consult a qualified compliance professional or your regulator before acting.


