Third-Party Reliance and Outsourced CDD in the UAE

Last updated: 26 July 2026

Third-party reliance and outsourced customer due diligence let a UAE business use another party’s CDD work instead of repeating every check itself. Both are permitted under Federal Decree-Law No. 10 of 2025 and Cabinet Decision No. 134 of 2025, but only under strict conditions, and one fact holds across both: the legal liability for the customer relationship never leaves your firm. Get the arrangement wrong and the penalty lands on you, not the party you leaned on.

This guide sets out the two models, the exact conditions for lawful reliance, the record-keeping you must keep, and an audit-readiness checklist your compliance officer can use before the next inspection.

Quick Answer: What is third-party reliance in UAE AML?

Third-party reliance is when a UAE regulated entity accepts CDD already performed by another regulated party rather than redoing it. Outsourcing is when you appoint a provider to perform CDD as your agent. Both are allowed under Cabinet Decision No. 134 of 2025, yet ultimate responsibility for the CDD always stays with your firm.

Key Takeaways

  • Two different models: reliance uses CDD another regulated party already did; outsourcing appoints an agent to do CDD on your instruction.
  • Liability never transfers: under Cabinet Decision No. 134 of 2025 the relying or outsourcing entity, and its compliance officer, keep full accountability.
  • Reliance has hard conditions: the third party must be regulated and supervised for AML/CFT, apply equivalent CDD, and hand over information immediately on request.
  • High-risk jurisdictions are off-limits: you cannot rely on a third party based in a country with weak AML controls.
  • Documented policy is mandatory: your AML programme must state where reliance is used, when CDD is outsourced, the controls, and each party’s responsibilities.
  • Records run five years minimum: longer in some free zones (six years in DIFC and ADGM, eight years for VARA-regulated firms).
  • Enforcement is personal: in June 2026 the CBUAE fined a compliance officer AED 300,000 for failing the duties of the role, with a separate AED 20 million fine on the institution.

What the UAE AML law says about using a third party

The framework changed in late 2025. Federal Decree-Law No. 10 of 2025 came into force on 14 October 2025 and replaced the older Federal Decree-Law No. 20 of 2018. Its executive regulations, Cabinet Decision No. 134 of 2025, took effect on 14 December 2025 and replaced Cabinet Resolution No. 10 of 2019.

Both instruments confirm that a financial institution, a designated non-financial business or profession (DNFBP), or a virtual asset service provider may rely on a third party or appoint an outsourced provider to carry out customer due diligence. The catch is in the conditions. The regulations require you to build documented policies and controls before you use either route, and they keep the responsibility for the outcome squarely with you.

Definition: reliance versus outsourcing

Reliance means you accept CDD that another regulated party has already completed on the same customer. A bank has onboarded the client, verified identity, and screened for sanctions; you take that work rather than starting again. You do not instruct the other party. You benefit from work it did for its own purposes.

Outsourcing means you hire a provider to perform CDD steps for you, on your instruction, as an extension of your own compliance function. The provider acts as your agent, follows your risk methodology, and reports to you. You direct the work and you own the result.

Reliance vs outsourcing: the differences that matter

Practitioners mix these two up, and the mix-up shows in an inspection. The table below sets out where they part ways.

Feature Reliance on a third party Outsourcing of CDD
Who performs the CDD Another regulated party, for its own purposes A provider acting as your agent
Who directs the work The third party, on its own methodology You, on your risk-based methodology
Written agreement Not always in place with you Required, defining scope and control
Access to underlying records On request, immediately Held on your behalf at all times
Ultimate responsibility Stays with your firm Stays with your firm
Typical use Introduced clients from a regulated introducer Capacity gaps, screening, document checks

The shared line at the bottom is the one regulators care about most. Whichever route you pick, the CBUAE, the Ministry of Economy, and the free-zone authorities treat the CDD as yours. Read the shared rule alongside our guide to customer due diligence in the UAE so the base obligations are clear before you delegate any of them.

The conditions for lawful reliance

You cannot simply accept another party’s file. Cabinet Decision No. 134 of 2025 and CBUAE guidance set conditions that must all be met before reliance is valid.

1. The third party is regulated and supervised

The party you rely on must be subject to AML/CFT regulation and supervision, and must apply CDD and record-keeping measures at least equal to the UAE requirements. Reliance on an unregulated introducer is not reliance in law; it is a gap.

2. You can obtain the information immediately

You must be able to get the CDD information from the third party without delay, and obtain copies of the identification data and supporting documents on request. If the party cannot produce the file quickly, the arrangement is not compliant and the exposure sits with you.

3. The customer is not routed through a high-risk country

Reliance on a third party located in a jurisdiction identified as high-risk, or with weak AML controls, is restricted. Screen the location of the introducer, not just the customer. The FATF lists of monitored jurisdictions are the reference point here.

4. Your compliance officer validates the file

The compliance officer must review and validate the CDD provided by the third party, confirming it is complete, current, and fit for your risk appetite. This is where reliance meets your own MLRO responsibilities, the officer signs off on work the firm did not perform, so the sign-off has to be real.

Mapping where reliance and outsourcing fit your programme? ADZ’s compliance advisory team helps UAE firms structure lawful reliance and outsourcing arrangements that hold up under inspection. Talk to ADZ about your AML obligations.

What outsourcing CDD requires

Outsourcing carries its own set of controls, because the provider is acting in your name.

  • A written agreement that defines the scope of work, the CDD steps covered, service levels, data protection, and audit rights.
  • Your methodology, not theirs. The provider applies your risk-based approach and your escalation rules, feeding results back for your decision.
  • Direct access to records. The CDD files are held on your behalf and available to you and to supervisors at any time.
  • Ongoing oversight. You monitor quality through sampling and periodic review, not a one-off onboarding of the vendor.
  • No delegation of judgement. The provider can gather and verify; the decision to accept a customer, apply enhanced checks, or file a report stays inside your firm.

Where a customer is higher-risk, outsourced collection still feeds your own enhanced due diligence process. The provider does the legwork; your compliance function makes the call.

The liability that never transfers

This is the point that most reliance failures come back to. Under Cabinet Decision No. 134 of 2025, delegating the work does not delegate the accountability. If the third party’s CDD was thin, the file was stale, or a sanctioned party slipped through, the supervisor holds your firm, and your compliance officer, to account.

The 2026 enforcement record makes the stakes concrete. In June 2026 the CBUAE fined the UAE branch of a foreign bank AED 20 million for repeated AML/CFT and sanctions failures, and separately imposed a personal penalty of AED 300,000 on its head of compliance and money laundering reporting officer for failing to fulfil the duties of the position. Across 2025 the CBUAE issued more than AED 370 million in AML/CFT penalties. Administrative fines under the executive regulations commonly run from AED 50,000 to AED 1,000,000 per violation, and legal-person court fines for serious cases reach AED 100,000,000.

The CBUAE’s April 2026 guidance reinforced the direction of travel: supervisors now assess whether controls are effective, not just whether they exist. A reliance arrangement that looks fine on paper but cannot produce a file, or rests on an unsupervised introducer, is an effectiveness failure, and that is what draws a penalty.

Want an independent view before the regulator forms one? ADZ conducts independent AML/CFT audits for CBUAE, DFSA, and VARA-regulated entities, including a targeted review of reliance and outsourcing arrangements. See ADZ’s independent audit services.

Where reliance and outsourcing show up by sector

The two models appear in different shapes across UAE sectors, and the risk sits in different places each time.

Real estate brokers

A broker often meets a buyer whose bank has already run full CDD. Relying on that bank’s work is legitimate, but the broker still has to obtain the file, confirm the bank is supervised, and screen the transaction for its own red flags. The introduced client does not switch off the broker’s reporting duty.

Dealers in precious metals and stones

Higher-value cash-adjacent trades push many dealers in precious metals and stones toward outsourcing document checks and screening to keep pace. The provider verifies identity and screens names; the dealer still decides whether a walk-in transaction is suspicious and whether to file.

Corporate service providers and VASPs

Corporate service providers frequently onboard entities introduced by law firms or banks, a classic reliance scenario, while virtual asset service providers often outsource identity verification and liveness checks to specialist vendors. In both cases the eight-year or five-year record trail and the immediate-access rule apply, and the compliance officer still owns the accept-or-reject decision.

Record-keeping for reliance and outsourcing

Records are the proof that a reliance or outsourcing arrangement was compliant. You must be able to reconstruct who did the CDD, what they checked, and when. Retention periods differ by regulator.

Regulator or zone Minimum retention
Federal (CBUAE, Ministry of Economy DNFBPs) 5 years
DIFC 6 years
ADGM 6 years
VARA (virtual assets) 8 years

Keep the CDD data, the supporting documents, the reliance or outsourcing agreement, and your compliance officer’s validation notes. The clock generally runs from the end of the business relationship or the date of the occasional transaction.

How to build a compliant reliance and outsourcing policy

Cabinet Decision No. 134 of 2025 expects a documented policy before you use either route. Use this skeleton as a starting structure.

  1. Scope statement. Name the customer types and circumstances where reliance is used and where CDD is outsourced.
  2. Eligibility criteria. Define what makes a third party or provider acceptable: regulated status, supervisory record, equivalent CDD, and geographic limits.
  3. Due diligence on the party. Set out how you assess and re-assess the introducer or provider before and during the arrangement.
  4. Information access. Specify the immediate-access requirement and the turnaround for producing full files on request.
  5. Validation and sign-off. Describe the compliance officer’s review of each relied-on or outsourced file.
  6. Responsibility matrix. State clearly what each party does and confirm that ultimate responsibility rests with your firm.
  7. Record-keeping. Fix the retention period for your regulator and the storage location.
  8. Escalation and exit. Define what happens when a party fails a review, including remediation and termination.

Tie the policy back to your enterprise-wide business risk assessment, so the level of reliance you allow matches the risk each customer segment carries.

MLRO audit-readiness checklist

Run this before an inspection or an independent audit. Each item should return a clear yes with evidence attached.

  • Is every introducer and provider confirmed as regulated and supervised for AML/CFT?
  • Can you produce any relied-on CDD file within the immediate-access standard?
  • Are all reliance and outsourcing arrangements covered by a documented policy?
  • Is there a written agreement for each outsourcing arrangement, with audit rights?
  • Has the compliance officer validated and signed off each relied-on file?
  • Are any introducers based in high-risk jurisdictions flagged and restricted?
  • Do retention records meet your regulator’s period (5, 6, or 8 years)?
  • Is oversight ongoing, with periodic sampling, not a one-off vendor check?
  • Does your responsibility matrix confirm liability stays in-house?

If any answer is no, that is a finding waiting to happen. Preparing for the wider examination is covered in our guide on how to prepare for a UAE AML inspection.

Managing reliance and outsourcing at scale? First Compliance automates CDD, sanctions and PEP screening, and goAML reporting, with the audit trail that proves each relied-on file was checked. Explore First Compliance.

Common third-party reliance mistakes UAE firms make

Most reliance failures are not exotic. They cluster around a handful of avoidable errors that inspectors see again and again.

  • Treating an unregulated introducer as a valid third party. If the party is not supervised for AML/CFT, there is no lawful reliance, only an unchecked customer.
  • No file on request. Firms accept the reliance in principle but never test whether the introducer can actually produce the CDD documents. The first real test comes during an inspection, which is too late.
  • Confusing reliance with a clean break. Some teams behave as if reliance ends their duties on that customer. Ongoing monitoring, screening, and reporting all continue.
  • Outsourcing the decision, not just the work. A provider can gather and verify. When a firm lets the vendor decide who to accept or whether to file, it has handed over judgement it is not allowed to delegate.
  • Skipping the geographic check. The customer may be low-risk while the introducer sits in a high-risk jurisdiction. Both need screening.
  • Stale validation. A one-time sign-off at onboarding, with no periodic re-check of the introducer or provider, drifts out of date and fails the effectiveness test the CBUAE now applies.

Fixing these is rarely expensive. It is mostly a matter of writing the policy, testing the file-access route once, and keeping the compliance officer’s validation live rather than one-off. Training the wider team so front-line staff understand what reliance does and does not cover closes the last gap.

Building the team knowledge behind these controls? Compliance 360 offers 32 KHDA-approved AML/CFT training courses, so your front-line and compliance staff know exactly where reliance stops. See Compliance 360 training.

Frequently Asked Questions

What is the difference between reliance and outsourcing of CDD in the UAE?

Reliance means accepting CDD another regulated party already performed on its own customer. Outsourcing means appointing a provider to carry out CDD as your agent, on your instruction. In both cases, under Cabinet Decision No. 134 of 2025, your firm keeps ultimate responsibility for the CDD.

Can you outsource customer due diligence in the UAE?

Yes. Federal Decree-Law No. 10 of 2025 and its executive regulations allow outsourced CDD, provided you have a documented policy, a written agreement, direct access to the records, and ongoing oversight of the provider. The decision to accept a customer or file a report cannot be outsourced.

Who is liable when a third party conducts CDD in the UAE?

Your firm is. Reliance and outsourcing do not transfer legal responsibility. If the CDD is inadequate, the supervisor holds the relying or outsourcing entity, and its compliance officer, accountable, as the CBUAE’s June 2026 personal penalty on a compliance officer showed.

Can you rely on a third party located in a high-risk country?

No. Reliance on a third party based in a jurisdiction identified as high-risk or with weak AML controls is restricted under UAE rules. Screen the introducer’s location as well as the customer’s, using the FATF lists as your reference.

How long must reliance and outsourcing records be kept in the UAE?

At least five years at federal level. DIFC and ADGM require six years, and VARA-regulated virtual asset firms must keep records for eight years. Retention generally runs from the end of the business relationship.

Does third-party reliance remove the need for ongoing monitoring?

No. Reliance covers the initial CDD only. You must still run ongoing monitoring, transaction screening, and suspicious activity reporting yourself throughout the relationship.

Should a UAE firm rely, outsource, or build in-house?

It depends on capacity, risk, and volume. Many firms combine all three. Our comparison of in-house versus outsourced AML compliance sets out the trade-offs for the UAE market.

Related Reading

Third-party reliance and outsourced CDD are legitimate tools for UAE compliance teams, but they are only as strong as the controls behind them. Confirm the third party is regulated, keep the records, validate every file, and remember the liability stays with you. ADZ helps UAE financial institutions, DNFBPs, and VASPs structure, document, and audit these arrangements. Contact ADZ for a consultation and gap analysis.

Disclaimer: This article is general information on UAE AML/CFT requirements as at July 2026 and is not legal advice. Confirm your obligations with your supervisory authority or a qualified adviser before acting. Outbound links point to official UAE and international regulatory bodies, including the Central Bank of the UAE and the UAE Ministry of Economy.

Scroll to Top