THE SCREENING SURFACE

Screening is only as strong as its coverage.

Sanctions exposure does not sit in one place. It reaches across the customer file, the ownership structure, the counterparties a business pays and the messages that carry those payments — which is why coverage, not software, is usually the first thing to fix.

Four surfaces that have to be covered.

A screening programme is judged on what it touches. These four areas account for most of the gaps EGRC finds when reviewing an existing sanctions framework, and each one needs its own trigger, owner and evidence.

→ Sanctions Risk Assessment

→ Targeted Financial Sanctions Compliance

→ Sanctions Policies & Procedures

→ Customer / UBO / Counterparty Screening

COVERAGE MAP

Where sanctions exposure actually sits.

Each surface needs its own screening trigger, owner and record. A gap in any one of them is the gap a reviewer will find first.

Customers and beneficial owners

Screening starts at onboarding and must reach through the ownership structure. Legal entities, directors, authorised signatories and ultimate beneficial owners all need to be tested — not just the name on the account.

Counterparties and intermediaries

Payment counterparties, correspondent institutions, agents, suppliers, vessels and trade parties sit outside the customer file but carry the same exposure, particularly in cross-border and trade finance activity.

Transactions and messages

Payment instructions, trade documentation and message fields are screened in flight. Free-text and reference fields matter, because that is often where a designated party or jurisdiction actually appears.

Ongoing re-screening

A clean result at onboarding is only valid until the next listing. When a list changes, the entire book should be re-tested, and that re-screen must leave a record that can be shown to a reviewer.

OBLIGATION FLOW

From designation to defensible record.

Targeted Financial Sanctions move quickly. The distance between a list changing and a firm being able to prove it acted is where most regulatory findings are made.

STEP 01 OF 04
01
A name is designated

A name is designated

United Nations Security Council designations flow into the UAE framework, and the Executive Office for Control and Non-Proliferation issues notifications to registered entities. The UAE also maintains its own Local Terrorist List, so relying on a single international list is not sufficient.

Your book is tested against it

Every customer, beneficial owner and counterparty is re-screened against the updated list. Alerts are triaged into true matches, potential matches requiring investigation, and discounted matches — each with a documented reason.

Freeze without delay

A confirmed match must be frozen without delay and within the timeframe prescribed by the applicable UAE requirements. No funds or assets may be dealt with, no services provided, and the customer must not be tipped off that a freeze or report is in progress.

Report and evidence it

Funds-freeze and partial-name-match reports are filed through the goAML platform and the relevant notification channels. Records of the decision, timing, approver and supporting evidence are retained so the action can be defended later.

SIGNAL AND NOISE

Most screening failures are tuning failures.

Screening rarely fails because a system was never bought. It fails because thresholds were left at vendor defaults, secondary identifiers were never used, and nobody recorded why an alert was discounted.

Tune the matching, not just the policy.

Arabic name transliteration, corporate name variants and shared common names all push false positives up. EGRC tunes matching logic against the names actually in your book, then evidences the tuning so the calibration itself can withstand review.

→ Fuzzy matching and Arabic name transliteration

→ Secondary identifiers: date of birth, nationality, ID number

→ Documented whitelisting and discount rationale

→ Testing with known-positive control samples

DRAG TO COMPARE

The same system, tuned.

Drag the handle to see the practical difference tuning and evidence make.

BEFORE

Vendor defaults, an unmanaged alert backlog, and freeze decisions nobody recorded.

WITH EGRC

Calibrated matching, a risk-prioritised queue, and freeze decisions with owners, timing and evidence.

WHAT CHANGES

The difference is evidence, not effort.

A sanctions framework is assessed on whether it can be demonstrated. This is the practical shift EGRC works toward on most engagements.

CapabilityTypical setupWith EGRC
List coverageUN list only, updated manuallyUN, UAE Local Terrorist List and relevant jurisdictional lists, with change monitoring
Matching logicVendor defaults, never testedCalibrated thresholds, tuned for name structures actually in the book
Alert handlingBacklog, inconsistent reasonsRisk-prioritised queue with documented discount rationale
FreezingInformal, undocumented timingDefined procedure with owners, timing and evidence of the freeze decision
AssuranceNo independent testingPeriodic independent review with remediation tracked to closure
INDEPENDENT REVIEW

An independent look before the regulator’s.

Independent review is not an audit of good intentions. It tests whether screening, escalation, freezing and reporting behave the way the policy claims they do.

Review, remediate, and close the loop.

EGRC provides independent sanctions reviews, screening system and threshold assessments, remediation planning and targeted training — with findings tracked through to closure so management can show what changed and when.

→ Independent sanctions review

→ Screening and threshold assessment

→ Remediation planning and tracking

→ Role-based sanctions training

COMMON QUESTIONS

Questions firms ask before scoping the work.

Practical answers to the sanctions questions that come up most often in UAE engagements.

Who has to screen against UAE Targeted Financial Sanctions?
All financial institutions and Designated Non-Financial Businesses and Professions operating in the UAE are expected to screen customers, beneficial owners and transactions against the applicable sanctions lists, and to act on confirmed matches. The obligation applies regardless of firm size — what changes with size is the proportionality of the control, not whether the control exists.
What does "freeze without delay" actually require?
On a confirmed match, the firm must immediately stop dealing with the funds or assets, apply the freeze within the timeframe prescribed by the applicable UAE requirements, avoid tipping off the customer, and report the action through the required channels. The practical implication is that the procedure, approval route and out-of-hours coverage all need to be worked out in advance — not improvised on the day.
Our screening system produces thousands of alerts. Is that normal?
High alert volume is common but it is usually a tuning symptom rather than a genuine risk signal. It typically comes from thresholds set too loosely, missing secondary identifiers such as date of birth or nationality, and no structured whitelisting of previously discounted matches. Tuning reduces the noise without weakening coverage, and a properly evidenced tuning exercise is itself a control a reviewer can inspect.
Is sanctions screening the same as AML screening?
They overlap but they are not the same obligation. AML controls are risk-based and allow judgement about the level of due diligence. Sanctions are strict liability — there is no risk appetite for dealing with a designated party. That is why sanctions controls, escalation and freezing procedures usually need to be documented separately, even where they run on the same system.
What is the Executive Office for Control and Non-Proliferation?
The Executive Office for Control and Non-Proliferation (EOCN) is the UAE body responsible for implementing targeted financial sanctions relating to terrorism and proliferation financing. It issues notifications about designations and expects registered entities to act on them. Firms are generally expected to subscribe to its notification system so that list changes reach the right people quickly.
How often should sanctions controls be independently reviewed?
Most firms benefit from an independent review at least annually, and sooner if the business model changes, a new payment channel or jurisdiction is added, the screening system is replaced or re-tuned, or an inspection is expected. An independent review looks at whether the control operates as documented — not simply whether the policy exists.
START WITH CLARITY

Discuss sanctions support.

Speak with EGRC about sanctions screening, TFS obligations, threshold tuning and independent review.

Discuss Sanctions Support