A periodic customer review is the process of re-checking the customer information you collected at onboarding, so that your AML controls still match the customer’s real risk. UAE AML regulators expect regulated businesses to prove that customer records are current, especially for high-risk customers.
This guide explains what the law requires, when a review must happen and how eKYC and automation make the process faster and easier to defend during an inspection. It is written for financial institutions, DNFBPs and virtual asset service providers, and for businesses looking for AML compliance services in the UAE.
What Does UAE AML Law Require for Periodic Customer Reviews?
The current framework is Federal Decree-Law No. 10 of 2025, which took effect on 14 October 2025, and its Executive Regulations, Cabinet Resolution No. 134 of 2025, in force since 14 December 2025. Together they replaced the 2018 law and the 2019 regulations.
Three provisions matter most:
- Article 8 requires ongoing monitoring throughout the business relationship. This includes scrutinising transactions against what you know about the customer, and keeping CDD documents, data and information up to date, with particular emphasis on high-risk customers.
- Article 7(1)(c) requires you to apply CDD again where there are doubts about the accuracy or adequacy of identification data you already hold.
- Article 21 requires internal policies, controls and procedures approved by senior management, and reviewed and updated on an ongoing basis.
The regulations do not fix a single review cycle for every business. Instead, you must set a risk-based schedule in your own policy and then follow it.
Why Getting This Wrong Is Costly
Weak periodic reviews are one of the easiest gaps for an inspector to find. Outdated records suggest that ongoing monitoring is not working.
The consequences are real:
- Administrative fines of AED 10,000 to AED 5,000,000 per violation under the Decree-Law, alongside warnings, restrictions on responsible individuals and possible licence suspension or revocation.
- A ban on continuing the relationship. Under Article 14, you must not continue a business relationship or execute a transaction if you cannot apply CDD, and you should consider filing a suspicious transaction report.
- Weaker suspicious activity detection, because stale profiles make transaction monitoring less accurate.
Three Triggers That Should Start a Customer Review
Build your policy around three types of trigger.
1. Risk-based reviews
Higher-risk customers need more frequent reviews. Article 5 supports this: enhanced due diligence can include updating CDD information more regularly, and simplified due diligence for low-risk customers can involve updating data at longer intervals.
2. Event-based reviews
Some events should trigger an immediate review, whatever the schedule says:
- A change in beneficial ownership, legal structure, registered address or business activity
- A customer becoming a politically exposed person (see Article 16)
- Adverse media, sanctions matches or legal proceedings involving the customer or its beneficial owners
- Transactions that do not fit the customer’s profile
- A change in the list of high-risk jurisdictions
- Findings from an internal or independent AML audit
3. Time-based reviews
These are the scheduled refreshes set in your policy. They also catch expiring documents such as Emirates IDs, passports, trade licences and visas.
Where eKYC and Automation Add Real Value
Manual reviews rely on spreadsheets and email chains, which break down as your customer base grows. Automation does not replace your judgement, but it removes repetitive work and creates an audit trail.
Digital identity verification: CBUAE guidance for licensed financial institutions recognises Emirates ID validation through the ICP online gateway and the UAE Pass application. DNFBPs commonly use it as a benchmark when designing remote onboarding.
Liveness and document checks: These support remote refreshes without a branch visit.
Expiry alerts: Systems can flag documents before they lapse and prompt a refresh.
Continuous screening: Automated checks against sanctions lists, PEP databases and adverse media can trigger an event-based review the moment a risk changes.
Transaction monitoring alerts: Unusual patterns can prompt a KYC refresh in near real time.
Case management and reporting: Workflows escalate high-risk cases to your compliance officer, and suspicious activity is reported through goAML without delay.
Technology brings its own obligations: Article 24 requires you to assess the money laundering, terrorist financing and proliferation financing risks of new technologies before you launch or use them. Article 20(3) confirms that outsourced processing must run under your own policies and supervision, so responsibility stays with you. Personal data collected through eKYC tools must also be handled in line with UAE data protection law.
A Practical Periodic Review Process
Use this sequence as a working template:
- Confirm the customer’s current risk rating and the review trigger.
- Request updated identification documents, and verify them through reliable, independent sources.
- Re-confirm beneficial owners (the 25% ownership test in Article 10) and any person acting on the customer’s behalf.
- Re-screen the customer, its beneficial owners and directors against sanctions, PEP and adverse media sources.
- Compare recent transactions with the expected profile and the stated source of funds.
- Re-rate the customer and escalate to senior management where enhanced due diligence applies.
- Record the outcome, the reasoning and the date of the next review.
- Decide whether a suspicious transaction report is needed. If so, file it immediately and do not tip off the customer (Article 19).
Frequently Asked Questions
How often should a UAE business review customer information?
The law requires information to be kept up to date, with emphasis on high-risk customers, but it does not set one fixed interval. You should define frequencies by risk category in your policy and follow them consistently.
Is eKYC allowed for periodic reviews in the UAE?
Yes, provided the verification relies on reliable and independent sources and you assess the technology’s risks first. Government-supported channels such as the ICP Emirates ID gateway and UAE Pass are recognised in CBUAE guidance.
What happens if a customer does not respond to a refresh request?
If you cannot complete CDD, Article 14 prohibits you from continuing the relationship or executing transactions, and you should consider filing a suspicious transaction report.
Does automation remove my responsibility as a regulated business?
No. You remain accountable for the accuracy of CDD, even when a vendor or outsourced provider carries out part of the process.
How long must review records be kept?
At least five years, counted as set out in Article 25 of Cabinet Resolution No. 134 of 2025.
How Jitendra Chartered Accountants Can Help
Our AML compliance services help UAE businesses build review processes that are practical and inspection-ready. We can support you with:
- A gap assessment of your CDD, KYC refresh and ongoing monitoring procedures
- Drafting or updating AML/CFT/CPF policies to reflect Federal Decree-Law No. 10 of 2025 and Cabinet Resolution No. 134 of 2025
- Customer risk assessment methodology and review-frequency design
- Independent testing of your AML controls, including an AML health check
- Compliance officer support, staff training and goAML reporting guidance
A periodic customer review is where AML policy meets daily practice. A clear risk-based schedule, defined event triggers, reliable eKYC tools and complete records are what turn a legal duty into a defensible control.
Need help with periodic customer reviews, KYC refresh or an AML health check? Speak to Jitendra Chartered Accountants today through our AML Compliance Services page and request a consultation.



