Re-KYC is an important part of ongoing Anti-Money Laundering (AML) compliance. While KYC begins when a customer is onboarded, Re-KYC ensures that customer information, beneficial ownership, risk profiles, and expected activities remain accurate throughout the business relationship.

Table of Contents

For businesses operating in the UAE, the Re-KYC process in UAE AML Compliance should be treated as an ongoing risk-management activity rather than simply a request for an updated Emirates ID, passport or company document.

A well-designed Re-KYC framework helps businesses identify changes in customer circumstances, ownership structures, source of funds, source of wealth, transaction behavior and geographic risk. It also supports customer due diligence (CDD), sanctions screening, ongoing monitoring and broader AML/CFT controls.

Key Takeaways

  • Re-KYC is the process of reviewing and updating existing customer KYC information.
  • Re-KYC supports ongoing customer due diligence and AML risk management.
  • Customer reviews should be based on customer risk and relevant regulatory requirements.
  • Event-driven Re-KYC may be required when significant changes occur.
  • Beneficial ownership, source of funds, source of wealth, and customer activity may need to be reassessed.
  • FATF grey-list status should be considered through a risk-based approach rather than automatically triggering enhanced due diligence for every customer.
  • Technology can support Re-KYC through automated reminders, screening, risk scoring, and audit trails.
  • Proper documentation is essential for demonstrating effective AML governance.

What Is Re-KYC in AML Compliance?

Re-KYC, or periodic KYC refresh, is the process of reviewing and updating customer information after the initial onboarding process.

KYC establishes who the customer is at the beginning of a business relationship. Re-KYC checks whether the information collected remains accurate, complete, and relevant as the relationship continues.

The review can cover identity information, business activities, beneficial ownership, source of funds, source of wealth, expected transaction activity, geographic exposure, and other risk factors.

The objective is not simply to collect new documents. The business should determine whether anything has changed that could affect the customer’s AML risk classification.

For UAE businesses, the Re-KYC process in UAE AML Compliance forms part of a broader framework that includes customer due diligence, ongoing monitoring, sanctions screening, risk assessment, and appropriate escalation of suspicious activity.

Why Is Re-KYC Important for UAE AML Compliance?

Keeping Customer Information Accurate

Customer information can change after onboarding. A customer may change their address, telephone number, business activity, ownership structure, or source of income.
Outdated information can weaken the effectiveness of KYC and customer due diligence controls.

Maintaining Accurate Customer Risk Profiles

AML risk is not static. A customer’s risk profile may change because of changes in geography, ownership, business activity, transaction patterns, or other risk indicators.
Re-KYC gives businesses an opportunity to reassess customer risk and determine whether additional measures are appropriate.

Identifying Beneficial Ownership Changes

Ownership structures can change through share transfers, acquisitions, restructuring or changes in control.
Businesses should identify and verify relevant ultimate beneficial owners (UBOs) and assess whether changes affect the customer’s AML risk.

See also  Customer Due Diligence in UAE: Complete AML CDD Guide

Supporting Ongoing Monitoring

Re-KYC should work together with transaction monitoring.
If a customer’s actual activity differs significantly from the expected profile established during onboarding, the business may need to investigate the reason and determine whether the customer’s KYC information should be refreshed.

Supporting Sanctions and PEP Screening

Customer and related-party screening should remain part of ongoing AML controls.
Businesses may need to rescreen customers and relevant parties against applicable sanctions lists and identify politically exposed persons (PEPs) or adverse media where relevant to their risk assessment.

Demonstrating Effective AML Governance

A documented Re-KYC framework helps demonstrate that AML controls are operating throughout the customer lifecycle rather than only during onboarding.
Businesses should retain evidence of reviews, information obtained, risk assessments, approvals and decisions.

KYC vs Re-KYC: What Is the Difference?

KYC

Re-KYC

Conducted primarily during onboarding

Conducted after onboarding

Establishes initial customer identity

Confirms whether customer information remains accurate

Creates the initial customer risk profile

Reviews and updates the existing risk profile

Collects initial CDD information

Refreshes relevant CDD information

Establishes expected activity

Compares updated expectations with actual activity

Both processes form part of effective customer due diligence.

What Information Should Be Updated During Re-KYC?

The information required will depend on the customer, business relationship, and risk profile.

Customer Identity

Businesses should verify relevant identification information and confirm that documents remain valid where applicable.

Address and Contact Information

Residential, registered office, correspondence and contact details may need to be reviewed.

Business Activity

For corporate customers, businesses should confirm whether the nature of the business, products, services, markets or operating model has changed.

Beneficial Ownership

Businesses should review ownership and control structures and identify relevant beneficial owners.

Source of Funds

Where relevant, businesses should understand the source of funds being used for transactions or the business relationship.

Source of Wealth

For higher-risk relationships, businesses may need to obtain and verify information regarding how the customer’s overall wealth was generated.

Expected Transaction Activity

The expected transaction profile should remain consistent with the customer’s known business activities, financial circumstances and risk profile.

Related Parties

Relevant directors, shareholders, beneficial owners, authorised representatives and other connected parties may require review.

Screening Information

Businesses should conduct appropriate sanctions, PEP and adverse-media screening based on their risk-based AML framework.

Does your real estate agency’s AML framework pass a Ministry of Economy inspection standard?

AMLUAE’s AML/CFT Health Check, delivered by specialist AML compliance consultants, assesses every element inspectors check, giving you a gap report and remediation roadmap before a regulator arrives.

When Should a Business Conduct Re-KYC?

There is no single review frequency that is appropriate for every customer.

A risk-based approach means businesses should determine review frequency according to the customer’s risk classification and applicable regulatory requirements.

Higher-risk customers may require more frequent reviews, while lower-risk relationships may be reviewed less frequently where permitted by the applicable framework.

Businesses should also define clear triggers for event-driven reviews.

What Is Event-Driven Re-KYC?

Event-driven Re-KYC occurs when a specific event indicates that customer information or risk should be reassessed.

Examples may include:

  • Significant changes in ownership or control
  • Changes in beneficial ownership
  • Major changes in business activities
  • Unusual transaction patterns
  • Significant changes in geographic exposure
  • New sanctions or PEP concerns
  • Material adverse media information
  • Changes in source of funds or wealth
  • Significant changes in customer risk

An event-driven review can occur before the next scheduled periodic review.

The 7-Step Re-KYC Process

1. Identify Customers Due for Review

Businesses should maintain a system that identifies customers requiring periodic or event-driven review.

2. Contact the Customer

Request relevant information and documentation according to the customer’s risk profile.

3. Collect Updated Information

Obtain updated KYC and CDD information where required.

4. Verify the Information

Information should be reviewed and verified using reliable and appropriate sources.

5. Conduct Screening

Conduct applicable sanctions, PEP, and adverse-media screening.

6. Reassess Customer Risk

Compare the updated information with the existing customer risk profile and determine whether the risk classification should change.

7. Document and Approve the Review

Record the information reviewed, decisions taken, risk changes, escalation, and approval where applicable.

Re-KYC and Customer Due Diligence

Re-KYC does not replace customer due diligence. Instead, it helps keep CDD information current throughout the customer relationship.

A business should consider whether the existing understanding of the customer remains accurate, including:

  • Who the customer is
  • What the customer does
  • Who ultimately owns or controls the customer
  • Where funds originate
  • What activity is expected
  • What transaction behavior has occurred
  • Whether risk factors have changed

The Re-KYC process in UAE AML Compliance should therefore be integrated with the wider CDD and ongoing monitoring framework.

Re-KYC, Source of Funds and Source of Wealth

Source of funds refers to the origin of specific funds involved in a transaction or business relationship.

Source of wealth relates more broadly to how a customer’s overall wealth was accumulated.

These concepts can become particularly relevant when transactions are inconsistent with the customer’s known profile or when a customer is classified as higher risk.

Businesses should avoid treating source-of-funds and source-of-wealth information as static. Where circumstances change, relevant information may need to be refreshed and reassessed.

See also  What Is MENAFATF? Members, Observers & UAE AML Guide

Re-KYC and Beneficial Ownership

Beneficial ownership is an important part of AML compliance because the person controlling or ultimately benefiting from a legal entity may not always be immediately apparent from its direct shareholders.

During Re-KYC, businesses should consider whether:

  • Ownership has changed
  • Control has changed
  • Shareholders have changed
  • UBO information remains accurate
  • Directors or authorised representatives have changed
  • The ownership structure has become more complex
  • New geographic or sanctions risks have emerged

Changes should be appropriately documented and assessed.

How FATF Grey-List Changes Affect Re-KYC

FATF’s increased-monitoring lists can be relevant to a business’s geographic and customer risk assessment.

However, being associated with a jurisdiction under increased monitoring does not automatically mean that every customer connected with that jurisdiction must be subject to blanket enhanced due diligence or refused service.

Businesses should consider the specific risk factors and apply a proportionate, risk-based approach.

Gray List Countries 2026: What Businesses Should Know

Businesses searching for gray list countries 2026 should distinguish between FATF’s official terminology, “jurisdictions under increased monitoring,” and informal references to the “grey list” or “gray list.”

FATF updates its lists periodically. Businesses should therefore use current FATF information when reviewing geographic risk rather than relying on outdated lists.

A customer’s connection to an increased-monitoring jurisdiction should be considered alongside other relevant factors, including customer type, business activity, transaction patterns, ownership structure and source of funds.

UAE FATF Mutual Evaluation 2026

The UAE’s AML/CFT framework is also relevant in the context of the country’s FATF mutual evaluation process.

FATF’s assessment calendar has listed the UAE under the FATF-MENAFATF assessment process, with an anticipated on-site assessment period in 2026 and a possible plenary discussion in 2027. Assessment schedules can change.

The UAE’s previous published mutual evaluation was conducted in 2020.

For businesses, the practical implication is that AML governance, risk assessment, customer due diligence, suspicious transaction reporting, beneficial ownership controls, sanctions screening and ongoing monitoring remain important areas of compliance.

UAE Money Laundering Compliance: What Should Businesses Have?

A strong UAE AML framework should be proportionate to the business’s size, activities and risk profile.

Depending on the applicable requirements, businesses may need appropriate:

  • AML/CFT policies and procedures
  • Business-wide AML risk assessment
  • Customer risk assessment
  • KYC and CDD procedures
  • Re-KYC procedures
  • Beneficial ownership controls
  • Sanctions screening
  • Transaction monitoring
  • Suspicious transaction reporting procedures
  • Record-keeping controls
  • AML training
  • Compliance governance
  • Internal controls and testing

The exact requirements depend on the business sector and applicable UAE regulatory framework.

The Role of AML Compliance Software in Re-KYC

AML compliance software can help businesses manage large customer populations and recurring compliance activities.

Depending on the system, technology can support:

  • KYC data management
  • Document expiry reminders
  • Customer risk scoring
  • Automated screening
  • PEP identification
  • Sanctions screening
  • Adverse-media checks
  • Transaction monitoring
  • Case management
  • Review workflows
  • Audit trails
  • Compliance reporting

Technology should support compliance professionals rather than replace appropriate human judgement.

A risk-based review may still require investigation and professional assessment, particularly for complex or higher-risk customers.

Re-KYC and AML Training

Employees involved in customer onboarding, compliance, operations, risk management or transaction monitoring should understand their responsibilities.

AML training can cover:

  • KYC procedures
  • Customer due diligence
  • Re-KYC procedures
  • Beneficial ownership
  • Source of funds
  • Source of wealth
  • Sanctions and PEP screening
  • Transaction monitoring
  • Suspicious transaction indicators
  • Internal escalation
  • Record keeping

Businesses looking for AML training courses in Dubai should consider whether the training is relevant to their industry, employee responsibilities, and UAE AML requirements.

What Is GoAML Training?

GoAML is the reporting platform used by the UAE Financial Intelligence Unit for relevant suspicious transaction and suspicious activity reporting.

GoAML training can help relevant compliance personnel understand the reporting process, information requirements, and internal procedures for escalation and submission.

Training should be aligned with the business’s reporting obligations and internal AML framework.

AML Compliance Dubai: What Should Businesses Look For?

Businesses searching for AML compliance Dubai services may require support with different aspects of their AML framework.

Depending on their needs, this can include AML policy documentation, risk assessments, KYC/CDD procedures, Re-KYC frameworks, transaction monitoring, sanctions screening, AML training, and regulatory compliance advisory.

When selecting an AML consultant, businesses should consider relevant UAE regulatory knowledge, industry experience, documentation quality, practical implementation capabilities, and ongoing support.

AML in UAE: Why a Risk-Based Approach Matters

The AML in UAE framework operates around risk-based principles. Businesses should understand their own risks and implement controls that are appropriate to their customer base, products, services, delivery channels, and geographic exposure.

A risk-based approach helps businesses allocate compliance resources according to the level and nature of risk.

This is particularly important for Re-KYC because not every customer presents the same level of risk and not every customer requires the same depth or frequency of review.

What Happens If a Customer Refuses to Complete Re-KYC?

If a customer does not provide required information or documentation, the business should follow its internal AML procedures and applicable regulatory requirements.

Depending on the circumstances, the business may need to:

  1. Request the missing information.
  2. Escalate the case internally.
  3. Review the customer’s risk classification.
  4. Consider whether continued service is appropriate.
  5. Apply relevant restrictions where required.
  6. Consider whether reporting or other regulatory action is necessary.

Businesses should avoid making automatic decisions without considering the facts and applicable requirements.

See also  CBUAE AML Fine 2026: AED 20 Million Bank Penalty and MLRO Personal Liability What Every UAE Business Must Learn

Common Re-KYC Mistakes UAE Businesses Should Avoid

Treating KYC as a One-Time Exercise

Customer information can become outdated. AML controls should address changes throughout the customer lifecycle.

Using the Same Review Frequency for Every Customer

Review frequency should reflect risk and applicable regulatory requirements.

Ignoring Beneficial Ownership Changes

Changes in ownership and control can materially affect customer risk.

Failing to Compare Expected and Actual Activity

Transaction behavior should be considered against the customer’s known profile.

Screening Only During Onboarding

Relevant screening should form part of ongoing AML controls.

Failing to Document Decisions

A review without an adequate audit trail can make it difficult to demonstrate how compliance decisions were reached.

Relying Entirely on Technology

Technology can automate processes, but complex cases may require professional review and judgement.

Confusing AML Advice With Tax Advice

AML compliance and tax compliance are different areas.

A tax consultant may provide tax-related advice, while an AML consultant focuses on AML/CFT obligations, financial crime risks, and related compliance controls.

Re-KYC Checklist for UAE Businesses

Before closing a Re-KYC review, businesses should consider whether they have:

  • Reviewed customer identification information
  • Updated relevant contact details
  • Confirmed business activities
  • Reviewed beneficial ownership
  • Checked relevant related parties
  • Reviewed source of funds where appropriate
  • Reviewed source of wealth where appropriate
  • Compared expected and actual activity
  • Conducted applicable sanctions screening
  • Reviewed PEP information
  • Considered adverse media where relevant
  • Reassessed customer risk
  • Documented decisions
  • Obtained appropriate approval
  • Scheduled the next review or recorded event-driven triggers

Why Work With AML UAE for Re-KYC and AML Compliance?

AML UAE can support businesses with practical AML and regulatory compliance requirements.

Tailored AML Compliance Frameworks

AML frameworks can be structured around the business’s activities, customer base, and risk profile.

AML/CFT Policies and Documentation

Businesses can receive support in developing and maintaining AML/CFT policies and procedures.

AML/CFT Risk Assessment

A business-wide risk assessment can help identify relevant customer, geographic, product, service, and delivery-channel risks.

KYC, CDD and Re-KYC Support

Businesses can strengthen their customer onboarding, customer due diligence, and ongoing customer review processes.

AML Training

Training can help employees understand their AML responsibilities and internal escalation procedures.

AML Compliance Software Guidance

Businesses can assess technology options for KYC, screening, transaction monitoring, workflow management, and audit trails.

Regulatory Compliance Advisory

Professional advisory support can help businesses understand and implement relevant compliance controls.

Ongoing AML Advisory Services

Ongoing advisory support can help businesses review and improve their AML framework as their operations and risk profile evolve.

Who Can Work With AML UAE?

AML compliance requirements vary according to the nature of the business and its regulatory status.

Businesses that may seek AML compliance support include relevant DNFBPs, financial-sector businesses, and other entities subject to applicable AML/CFT obligations.

The appropriate compliance framework should always be determined according to the entity’s activities, regulator, and applicable UAE legislation and regulations.

AML UAE: Your AML Compliance Partner in the UAE

Effective AML compliance requires more than creating a policy document.

Businesses need practical processes for KYC, customer due diligence, risk assessment, Re-KYC, screening, transaction monitoring, reporting, training, and compliance governance.

AML UAE provides AML compliance solutions, advisory, and implementation support designed around the needs of businesses operating in the UAE.

Ready to Strengthen Your AML Compliance?

AML UAE can support businesses with:

Conclusion

Re-KYC is an essential component of ongoing AML compliance because customer risk does not remain static throughout a business relationship.

A robust Re-KYC framework helps businesses maintain accurate customer information, identify beneficial ownership changes, reassess customer risk, review transaction behavior, and support ongoing screening and monitoring.

For UAE businesses, the Re-KYC process in UAE AML Compliance should be integrated with the wider AML/CFT framework rather than treated as an isolated administrative exercise.

Businesses should combine appropriate policies, risk-based procedures, employee training, technology and professional oversight to maintain effective AML controls.

Get Expert AML Support From AML UAE

Call: +971 52 573 3730

Email: connect@amluae.ae

Frequently Asked Questions About Re-KYC Process in UAE AML Compliance

What is Re-KYC in AML compliance?

Re-KYC is the process of reviewing and updating customer information after initial KYC onboarding. It helps businesses determine whether customer identification, beneficial ownership, source of funds, source of wealth, expected activity, and customer risk information remains accurate. Re-KYC can be periodic or event-driven depending on the customer's risk profile and applicable regulatory requirements. It forms part of ongoing customer due diligence and AML risk management.

How often should Re-KYC be conducted in the UAE?

Re-KYC frequency should generally be determined using a risk-based approach and according to applicable regulatory requirements. Higher-risk customers may require more frequent reviews, while lower-risk customers may be reviewed less frequently where permitted. Businesses should also conduct event-driven reviews when significant changes occur, such as ownership changes, unusual activity, new sanctions concerns, or material changes in customer circumstances.

What documents are required for Re-KYC?

The documents required depend on the customer type and risk profile. They may include identity documents, proof of address, company documents, ownership information, UBO documentation, source-of-funds evidence, and source-of-wealth information where appropriate. Businesses should avoid requesting documents without considering their relevance to the customer's risk and the purpose of the review.

Does a FATF grey-listed country automatically require enhanced due diligence?

No. FATF's approach does not mean that every customer connected to a jurisdiction under increased monitoring must automatically be subjected to blanket enhanced due diligence or de-risking. Businesses should apply a risk-based approach and consider the customer's individual circumstances, transaction activity, ownership, geographic exposure and other relevant risk factors.

What is the UAE FATF mutual evaluation 2026?

The UAE is undergoing the FATF-MENAFATF mutual evaluation process. FATF's assessment calendar has indicated an anticipated onsite assessment period in 2026, with a possible plenary discussion in 2027. Assessment dates can change. Businesses should focus on maintaining effective AML/CFT controls rather than relying on assumptions about the outcome of an ongoing assessment.

Can AML compliance software automate Re-KYC?

AML compliance software can automate parts of the Re-KYC workflow, including customer review reminders, document tracking, sanctions screening, risk scoring, workflow management, and audit trails. However, technology does not eliminate the need for appropriate human review. Complex or higher-risk customers may require additional investigation and professional assessment.

What is the difference between an AML consultant and an AML advisor?

The terms AML consultant and AML advisor are often used interchangeably. In practice, an AML professional may provide services such as AML risk assessments, policy development, KYC/CDD frameworks, Re-KYC procedures, training, screening controls, and regulatory compliance advisory. Businesses should evaluate the provider based on its relevant expertise, scope of services, and knowledge of applicable UAE requirements.

Is AML training required for UAE businesses?

Relevant UAE businesses subject to AML/CFT requirements should provide appropriate training to employees involved in AML-related responsibilities. Training should reflect the business's activities and risks and may cover KYC, CDD, Re-KYC, beneficial ownership, sanctions screening, transaction monitoring, suspicious activity indicators, and internal reporting procedures.

What is GoAML training?

GoAML training helps relevant personnel understand the UAE suspicious transaction and suspicious activity reporting process using the GoAML platform. Training can cover reporting workflows, information requirements, internal escalation, and practical reporting procedures. The exact reporting obligations depend on the business and its applicable regulatory requirements.

Can an AML consultant help with Re-KYC?

Yes. An AML consultant can help businesses design or improve Re-KYC procedures, customer risk assessment frameworks, CDD processes, screening controls, documentation, and review workflows. Professional support can also help identify gaps between existing procedures and applicable regulatory expectations.