Across the Middle East and North Africa, compliance expectations have tightened sharply following FATF mutual evaluations and the UAE's exit from the grey list. Supervisors now look for demonstrable, technology-supported controls rather than manual files — and they test whether reporting actually reaches the Financial Intelligence Unit on time.
The regional variables are concrete: a fragmented KYB landscape split between mainland authorities and free zones, Arabic-script names that romanise in many different ways, sanctions exposure to UN, local, OFAC, UK and EU regimes at once, and data residency expectations that vary by regulator. Generic software built for a single Western market rarely handles all four.
The MENA obligations your software has to carry
- UAE Federal Decree-Law No. 20 of 2018 and Cabinet Decision No. 10 of 2019 — risk-based CDD, EDD, record keeping and reporting.
- Central Bank of the UAE, SCA, DFSA (DIFC) and FSRA (ADGM) sector rulebooks, each with their own AML guidance and inspection style.
- goAML filing for suspicious transaction and suspicious activity reports, plus high-risk country and fund-freeze reports.
- Local terrorist lists and UN Security Council consolidated designations, alongside OFAC, UK and EU lists for internationally exposed firms.
- Saudi Arabia's AML Law and SAMA guidance, Qatar's QFCRA rules and Bahrain's CBB rulebook for firms operating across the Gulf.
- Data protection and residency: UAE Federal Decree-Law No. 45 of 2021, DIFC and ADGM data protection regimes, and Saudi PDPL.
KYB across mainland and free zones
| Entity type | Registry / authority | Practical issue |
|---|---|---|
| UAE mainland company | Emirate-level Department of Economic Development | Licence data varies by emirate; trade licence is the key artefact |
| DIFC entity | DIFC Registrar of Companies | Common-law structures with separate filings |
| ADGM entity | ADGM Registration Authority | Separate register and beneficial ownership regime |
| Other free zones | Individual free-zone authorities | Dozens of registries, limited machine-readable access |
| Saudi company | Ministry of Commerce commercial register | Arabic-first records requiring translation and matching |
Arabic name screening done properly
The same Arabic name can be romanised as Mohammed, Muhammad, Mohamad or Mohd, and naming conventions include patronymics, tribal names and honorifics that shift word order. Exact-match screening misses designations; naive fuzzy matching buries analysts in noise.
What works is transliteration-aware matching with configurable thresholds by risk tier, script-native matching on the original Arabic where available, and disposition reasons recorded per alert so a supervisor can see why a match was cleared.
What MENA buyers should test in a demo
- Screen a transliterated name in three spellings and compare the alerts produced.
- Onboard a free-zone entity and check which registry data is retrieved automatically versus uploaded manually.
- Ask to see the goAML-ready output from a case, not just an internal PDF.
- Confirm hosting region and how the platform meets your regulator's data residency expectation.
- Verify support hours align with Gulf working weeks, including Friday coverage arrangements.
How Infocredit Group supports MENA firms
Infocredit Group runs a Dubai office in Jumeirah Lakes Towers alongside its Cyprus headquarters, serving Gulf and African clients. ComplianceSuite covers KYC/KYB onboarding, multi-regime sanctions and PEP screening with transliteration-aware matching, adverse media and continuous monitoring with regulator-ready evidence. RISQO scores counterparties across ten risk dimensions, and API4ALL lets MENA firms search companies and order Credit, KYB and Structure reports directly inside their existing onboarding systems.
Frequently asked questions
What compliance software do UAE firms need?
UAE firms need software aligned to Federal Decree-Law No. 20 of 2018 and Cabinet Decision No. 10 of 2019: risk-based customer due diligence, enhanced due diligence for PEPs and high-risk relationships, screening against UN and local lists plus OFAC, UK and EU where exposed, ongoing monitoring, and case workflow that produces goAML-ready reports.
How does goAML reporting affect software choice?
Suspicious transaction and activity reports in the UAE are filed through the goAML portal, so the platform's case management should capture the required fields during investigation and export in a structure that maps to goAML rather than forcing analysts to re-key a report under time pressure.
Do DIFC and ADGM firms follow the same rules as mainland UAE?
They follow the federal AML framework but are supervised by the DFSA and FSRA respectively under their own rulebooks, with separate company registries and data protection regimes. Software should support both the federal reporting path and the financial free zone's supervisory expectations.
How should screening handle Arabic names?
With transliteration-aware fuzzy matching that recognises multiple romanisations of the same Arabic name, script-native matching on original Arabic records where available, risk-tiered thresholds, and recorded disposition reasons so a supervisor can audit why each potential match was cleared or escalated.
Is data residency required for compliance data in the Gulf?
Requirements vary by regulator and sector. Some supervisors expect in-country or in-region hosting for regulated data, and DIFC, ADGM and Saudi PDPL each impose their own transfer conditions, so confirm the hosting region and transfer mechanism before contracting.
Compliance insights, straight to your inbox
Monthly analysis on AML, screening and risk technology from the teams behind ComplianceSuite, RISQO and API4ALL. No spam — unsubscribe anytime.
