Middle East and GCC Financial Crime Controls
A multinational bank cannot manage the Gulf Cooperation Council as if it were one AML rulebook. Bahrain, Kuwait, Oman, Qatar, Saudi Arabia and the United Arab Emirates share many familiar financial-crime control objectives, and all are connected to the FATF standards through their national frameworks and regional cooperation. The legal source, supervisor, financial intelligence unit, reporting route, sanctions implementation, licensing perimeter and data-handling constraints nevertheless remain jurisdiction-specific.
That distinction is the starting point for this chapter. The useful mental model is one group financial-crime control framework over several local legal and regulatory planes. Group policy can set minimum standards for customer due diligence, beneficial-ownership analysis, transaction monitoring, sanctions screening, case management, quality assurance and governance. It cannot replace the local law that determines who must report suspicion, which authority receives the report, what must be frozen, when a customer can be told something, which regulator supervises a particular entity, or what information can be moved across borders.
The region also contains multiple regulatory perimeters inside the same country. In the UAE, for example, a bank or financial institution may operate under the federal framework and CBUAE supervision, while firms in the Dubai International Financial Centre are supervised by the DFSA and firms in Abu Dhabi Global Market by the FSRA. Qatar similarly has the State framework alongside the Qatar Financial Centre and QFCRA rules. Those structures do not erase national AML/CFT law, but they matter greatly for operating procedures, regulatory notifications, reporting ownership and the evidence an institution must retain.
Start with the global standard, then localise it
The FATF Recommendations are the common international reference point. They establish expectations around risk assessment, customer due diligence, beneficial ownership, suspicious-transaction reporting, record keeping, correspondent banking, wire transfers, targeted financial sanctions and supervision. FATF updated Recommendation 6 in June 2026 to align targeted financial sanctions for terrorism and terrorist financing with relevant UN humanitarian exemptions. That is a useful reminder that even a global standard is not static.
For a bank, FATF should therefore be treated as the common language, not as the transaction-level legal instruction. A requirement such as “identify the beneficial owner” still has to be mapped to the applicable customer type, local law, regulatory guidance, evidence standard and system field. A requirement such as “freeze without delay” still has to be mapped to the relevant local targeted-financial-sanctions framework, list source, match-decision process, licence or exemption handling, reporting route and release authority.
This approach prevents two common errors. The first is regional over-generalisation: taking a rule from one GCC jurisdiction and describing it as a Gulf-wide requirement. The second is group-policy overstatement: applying US, EU or UK sanctions policy because the bank chooses or is required to do so, then describing that policy restriction as if it were automatically local law. A mature institution records both layers separately.
A practical jurisdiction map
The comparison below is deliberately operational rather than encyclopaedic. It gives the learner enough structure to understand where local ownership sits while preserving the need for current legal interpretation.
| Market | Important banking AML/CFT anchors | FIU / reporting lens | Sanctions and supervision lens | Practical design lesson |
|---|---|---|---|---|
| United Arab Emirates | Federal Decree-Law No. 10 of 2025 and Cabinet Decision 134/2025, plus sector guidance | UAE Financial Intelligence Unit; goAML is used for suspicious transaction/activity reporting | CBUAE for its licensed population; DFSA in DIFC; FSRA in ADGM; local TFS framework includes UN-related measures and local terrorism lists | Store legal entity and regulator as first-class data; do not treat “UAE” as one supervisory workflow |
| Saudi Arabia | Anti-Money Laundering Law, Counter-Terrorism Financing law and SAMA rules/guidance for supervised financial institutions | Saudi Financial Intelligence Unit / General Directorate of Financial Intelligence receives and analyses suspicious reports | SAMA supervisory expectations, national legal framework and competent authorities for sanctions/TFS | Reporting, monitoring and board governance need explicit Saudi controls rather than a generic GCC setting |
| Qatar | Law No. 20 of 2019, QCB AML/CFT instructions and related national framework | Qatar Financial Information Unit | QCB-regulated firms and QFC/QFCRA firms have different supervisory rule sets, while national criminal/AML laws still matter | Separate State and QFC supervisory obligations without duplicating the same customer facts unnecessarily |
| Bahrain | CBB Rulebook Financial Crime modules and national AML/CFT framework | Local competent reporting authority under Bahrain framework | CBB supervision and rulebook controls | Version rulebook obligations by licence type; do not assume one module applies identically to every licensee |
| Oman | Royal Decree 30/2016 AML/CFT law and CBO supervisory instructions; Banking Law was replaced by Royal Decree 2/2025 | National Centre for Financial Information under the national framework | CBO supervision of licensed institutions and national targeted-measures implementation | Keep prudential/licensing change separate from AML law change, but assess operational dependencies together |
| Kuwait | Law No. 106/2013 and CBK AML/CFT instructions for supervised institutions | Kuwait Financial Intelligence Unit is the independent national FIU | CBK supervision; national mechanism implements relevant UN Security Council measures | Model FIU reporting and CBK supervision as related but separate responsibilities |
The table is not a substitute for local counsel or current regulator instructions. Its purpose is to show what the technology and operating model must be able to represent.
The UAE: federal law, sector supervision and financial free zones
The UAE is a good example of why jurisdiction design has to go below the country level. Federal Decree-Law No. 10 of 2025 on combating money laundering, terrorist financing and proliferation financing took effect on 14 October 2025, and Cabinet Decision 134/2025 provides the implementing regulation. By September 2026, these are the current federal anchors and should replace training that still presents the 2018 law as the sole current framework.
For institutions supervised by the Central Bank of the UAE, the CBUAE rulebook and AML/CFT supervision material translate federal obligations into practical expectations. The CBUAE currently supervises a broad population including banks, exchange houses, finance companies, payment service providers, payment-token service providers, registered hawala providers and insurance-related entities within its remit. The exact perimeter should always be checked because licence categories evolve.
Suspicious reporting is made to the UAE FIU. The FIU’s goAML portal supports suspicious transaction and suspicious activity reports, and the FIU publishes submission guidance. Operationally, that means a bank needs more than a “file SAR” button. It needs registered users, role-based access, a controlled mapping from case data to the reporting schema, evidence of submission, FIU reference capture, request-for-information handling and a protected record of what was filed. The case record should preserve the version that was sent, because an investigator may continue to add information after submission.
Targeted financial sanctions are a separate decision path. The CBUAE states that licensed financial institutions must implement the UAE targeted-financial-sanctions framework, including relevant Cabinet measures, UN Security Council obligations and guidance issued by the Executive Office for Control and Non-Proliferation. A potential name match therefore needs identity resolution, ownership/control analysis where relevant, a legal-applicability check, timely disposition and evidence of any freeze, rejection, release or report. Suspicion reporting and sanctions reporting may arise from the same facts, but they are not interchangeable legal actions.
The DIFC and ADGM add another layer. The DFSA amended its AML module in 2026 to align with the new federal AML legislation. The ADGM FSRA likewise finalised enhancements to its AML framework in May 2026, including changes reflecting federal law and FATF developments. The correct operating model is not “free zones are outside UAE AML law.” Rather, the institution must understand the interaction between federal law and the relevant financial-free-zone regulator’s rulebook, notification and supervisory expectations.
This matters in shared-service architecture. A group screening engine may serve an onshore UAE bank, a DIFC entity and an ADGM entity. The list-management service can be common, but case routing, legal basis, notification fields, accountable MLRO and regulator-facing evidence may differ. A single disposition value such as SANCTIONS_HIT is not sufficient. The data should preserve entity, regulator, applicable regime, match basis, legal action, reporting authority, timestamps and approver.
The UAE also illustrates why trade and transshipment risk cannot be handled by name screening alone. CBUAE guidance effective from November 2025 addresses trade-based money laundering and transshipment risks and recognises the relevance of ports, financial free zones and commercial free zones in a major trading hub. A bank serving importers, exporters, logistics firms or commodity traders should therefore connect customer profile, invoices, counterparties, goods description, shipping route, payment data and sanctions/export-control indicators where it actually has those data. The bank should not claim visibility it does not possess.
Saudi Arabia: strong local ownership and direct FIU reporting
Saudi financial institutions operate under the Kingdom’s AML and counter-terrorism-financing laws and SAMA supervisory framework. SAMA’s AML/CTF Guide remains an important operational reference for supervised financial institutions, and SAMA issued additional guidance at the end of 2025 on assessing business risks related to money laundering, terrorist financing and proliferation financing. That guidance is expressly risk-based: it identifies minimum factors to consider but does not prescribe one universal assessment method.
The practical value of the Saudi framework is that it makes governance expectations visible. Risk assessment should not sit as a compliance spreadsheet disconnected from products. Customer types, delivery channels, geographies, products, emerging technology and observed typologies need to feed the institution’s view of exposure. Before launching new products, services or technologies, the financial-crime risk assessment should be part of approval rather than an afterthought.
Suspicious activity is reported to the Saudi Financial Intelligence Unit, also described in the legal framework as the General Directorate of Financial Intelligence under the Presidency of State Security. SAMA guidance requires effective internal escalation, sufficient investigation, confidentiality and direct reporting when reasonable grounds for suspicion exist. It also requires institutions to document decisions not to report internal suspicion cases. That last point is operationally important: a closed internal alert is still a governed decision.
A good Saudi case-management workflow should therefore distinguish at least four states: an automated or manual signal, an internal suspicion referral, an MLRO/authorised decision on external reporting, and the external FIU report with its protected evidence. Closing the first state must not accidentally imply that no human concern was ever raised. Likewise, filing externally must not make the report visible to customer-facing teams in a way that creates tipping-off risk.
Saudi Arabia’s rapid growth in digital payments, fintech and new financial products also makes change governance important. The control question is not whether a new channel is “digital” but whether the bank understands identity, device, beneficiary, velocity, funding source, merchant or wallet context, and whether monitoring and investigation can keep pace with settlement speed. SAMA’s risk-assessment expectations provide the governance frame; the bank still has to design scenarios and data coverage appropriate to its own business.
Qatar: State framework and QFC overlay
Qatar’s Law No. 20 of 2019 is a core national AML/CFT anchor. QCB issues AML/CFT instructions for financial institutions under its supervision, while the Qatar Financial Information Unit receives and analyses suspicious reports. QFIU continues to publish guidance and was actively conducting public-private engagement and training in 2026, which reinforces the point that reporting quality is an operating capability rather than a static legal clause.
For firms in the Qatar Financial Centre, the QFCRA maintains its own AML/CFT rules and supervision. Its framework is underpinned by State Law No. 20 of 2019 and related national legislation. QFCRA material also makes clear that firms reporting an STR to QFIU may have a separate obligation to notify the QFCRA through the regulatory process. That is a useful example of one event creating two distinct communications: the confidential suspicious transaction report to the FIU and a regulator notification required by the supervisory rulebook.
A system should not merge those into one outbound message. The FIU submission contains investigative information protected by confidentiality rules. A regulator notification may have a different form, purpose, recipient and data scope. The case timeline should prove both actions occurred without exposing the FIU report more widely than authorised.
Bahrain, Oman and Kuwait: do not let smaller footprints become weaker controls
A global bank may have less business in Bahrain, Oman or Kuwait than in the UAE or Saudi Arabia. That is not a reason to use a vague “rest of GCC” configuration. Lower transaction volume can actually make local knowledge more important because a central team may see fewer examples and have less intuitive understanding of local products, customer structures and reporting processes.
The Central Bank of Bahrain Rulebook contains Financial Crime modules covering AML/CFT systems and controls, MLRO responsibilities, suspicious transaction reporting, record keeping, designated persons and entities, training and enforcement. The details vary by licence volume and module. For architecture, the implication is simple: the customer or case record needs the legal entity and licence type so the procedure and control library can resolve the correct obligations.
Oman’s AML/CFT framework includes Royal Decree 30 of 2016 and CBO supervisory instructions. The CBO also notes that the Banking Law was replaced by Royal Decree 2/2025. The new banking law is not itself an AML replacement, but organisational, licensing and technology changes can affect AML controls. If a digital bank or payment service operates under a new regulatory framework, the financial-crime team needs to confirm that onboarding, monitoring, reporting and governance remain correctly mapped.
Kuwait’s AML/CFT framework includes Law No. 106 of 2013 and CBK instructions. The Kuwait Financial Intelligence Unit is an independent body established under that law and receives, analyses and refers information concerning suspected proceeds and potential money-laundering or terrorist-financing activity. CBK has also highlighted that supervised banks and exchange companies should submit suspicious reports directly to the KFIU and comply with the national mechanism for implementing relevant UN Security Council measures.
The architecture lesson across all three markets is local specificity without unnecessary system duplication. A bank does not need six unrelated case platforms. It does need configurable legal-entity routing, local procedure links, FIU/reporting destinations, sanctions obligations, retention rules, access controls and approval roles.
Where risk appears in the customer and payment lifecycle
A regional financial-crime programme should not be built around a list of stereotypes. Geography alone is not proof of suspicion. The bank should instead identify how its actual products, customers and channels create exposure and what evidence can distinguish legitimate activity from misuse.
At onboarding, relevant questions include legal form, beneficial ownership, controlling persons, business activity, expected counterparties, operating countries, source of funds, source of wealth where appropriate, purpose of the relationship and expected payment profile. Free-zone registration can be commercially legitimate; the risk question is whether ownership, business purpose and transaction behaviour are coherent and verifiable. The same principle applies to family-owned groups, holding companies and cross-border structures.
For exchange houses and remittance businesses, the bank should understand licensing status, agent or correspondent relationships, settlement model, customer base and expected corridors. High remittance volume is not suspicious merely because migrant-worker remittances are common in the region. Risk emerges when observed behaviour is inconsistent with the business model, when counterparties are opaque, when funds move through unexplained intermediaries, or when unusual patterns cannot be supported by evidence.
Trade finance and commercial payments require a different lens. Import/export customers may generate large cross-border flows supported by invoices and shipping documents. Detection can use mismatches among customer profile, goods, value, counterparty, country, vessel or route information, but only where the bank receives or can lawfully obtain those data. Generic keyword screening of invoice text is not a substitute for trade-risk analysis.
Correspondent banking adds nested-party and transparency risk. A GCC bank may process payments for respondent institutions, remitters or other financial institutions across the region and beyond. The correspondent should understand the respondent’s business, ownership, regulatory status, AML controls, downstream access and expected activity in line with applicable policy and law. Monitoring should then test whether actual flows fit that understanding.
Private banking and wealth relationships may require stronger source-of-wealth analysis, especially where complex companies, trusts, investment vehicles or cross-border family structures are involved. The control should avoid equating wealth with suspicion. The objective is to establish how the wealth was generated, whether the evidence is credible, who ultimately controls assets and whether transactions remain consistent with the profile.
Islamic finance changes contractual form but does not remove financial-crime risk. Murabaha, ijara, sukuk or other Sharia-compliant structures can create multiple contractual parties and asset legs that systems need to understand. The bank should map the economic purpose, counterparties and payment flows rather than assume conventional-product monitoring fields will always capture the same information.
Sanctions, TFS and group overlays
The safest way to design regional sanctions controls is to separate four questions.
First, what local targeted-financial-sanctions obligations apply to this legal entity? These are grounded in national law and implementation of relevant UN Security Council measures, and may include domestic terrorism lists or other national measures.
Second, what additional regimes apply because of the bank’s structure, currency, people or transaction route? A transaction involving a US person, US branch or another jurisdictional nexus can create additional obligations. That analysis belongs to approved legal and sanctions policy, not to guesswork in the payment engine.
Third, what broader group risk appetite applies? A global bank can decide not to offer certain activity even where local law does not prohibit it. The customer and operations teams should be able to distinguish “prohibited by law” from “not permitted by group policy.”
Fourth, what operational action follows? Potential match, confirmed match, freeze, reject, hold, seek information, release, report or escalate are not synonyms. The system should record the authority for the action and the evidence used.
This distinction becomes especially important when sanctions lists change quickly. List ingestion should be source-controlled, time-stamped and tested. Screening should preserve the list version used for a decision. Rescreening should be triggered according to policy when customer or list data change. Operations must have a controlled path for urgent true matches without improvising customer communication.
A joined control architecture
A strong GCC operating model connects five control layers rather than treating them as separate compliance tools.
The customer layer contains identity, entity, ownership, controllers, products, expected activity and risk assessment. The screening layer evaluates customers, connected parties, payments and relevant trade data against applicable sanctions and other risk lists. The behaviour layer monitors transactions and relationships for deviations, typologies and unusual patterns. The case layer combines alerts with customer, payment and external evidence so an investigator can make a defensible decision. The regulatory action layer handles FIU reporting, sanctions actions, regulator notifications and law-enforcement requests under controlled access.
A sixth layer sits across all five: evidence and governance. Every material decision should be reconstructable. The bank should be able to show which data arrived, which rule or model fired, what enrichment was performed, who reviewed the case, what information was missing, which policy version applied, who approved the outcome and what external action was taken.
Data design and integration touchpoints
For business analysts and architects, the most important design choice is to avoid burying legal applicability inside free text. At minimum, a regional financial-crime platform should be able to represent legal entity, branch, booking location, regulator, licence type, customer country, incorporation country, operating countries, product, channel, customer risk rating, beneficial owners, controllers, screening regimes, applicable policy version, alert source and external reporting authority.
Payment data should preserve the original message as well as normalised fields. ISO 20022 can provide structured debtor, creditor, ultimate-party, agent, address, purpose and remittance information, but the institution still has to manage missing, truncated or poorly mapped data. A sanctions or monitoring engine should know whether a field is absent because the originating message lacked it, because the bank’s mapping dropped it, or because a downstream system does not support it. Those are different control problems.
Trade data introduces additional entities: buyer, seller, shipper, consignee, vessel, port, goods description, invoice value, currency, incoterms and documents. Not every bank product exposes all of these. The control inventory should therefore identify data availability by product and channel rather than assume a universal trade record.
Case systems need jurisdiction-aware confidentiality. An investigator in a regional hub may need access to customer and transaction information from several countries, but access to FIU reports, law-enforcement requests or sensitive personal data may be more restricted. Role-based access should be supplemented by purpose, entity and case-level controls where required. Audit logs should show views, exports and changes to sensitive records.
Alert to investigation to reporting
An alert is not a legal conclusion. The first task is to understand why the control triggered and whether the data are reliable. A sanctions alert may be caused by a common name; a transaction-monitoring alert may reflect a legitimate seasonal business peak; a trade alert may result from an incomplete goods description. The reviewer should verify the signal before escalating risk language.
The investigation then asks whether the activity is consistent with what the bank knows. Useful evidence may include KYC/KYB records, ownership data, account history, counterparties, payment messages, customer explanation, contracts, invoices, public records and previous cases. The investigator should distinguish facts from inference. “Payment to Company X in Country Y” is a fact. “Likely sanctions evasion” is a hypothesis that requires evidence.
If suspicion is formed, the responsible local decision maker follows the applicable reporting process. One regional case may require more than one local assessment if multiple group entities are involved. The platform should not simply mark the whole group case SAR_FILED = YES. It should store each reporting decision by legal entity, jurisdiction, FIU, date, reference and decision owner.
If no external report is made, the closure rationale still matters. A defensible closure explains why the activity is understood, what evidence supports that conclusion and whether any customer-risk or monitoring changes are needed. Repeated “false positive” closures can reveal poor scenario design or stale customer profiles even where no case is suspicious individually.
Governance and the three lines
First-line business and operations own customer relationships, accurate data capture and execution of many controls. They should know when to escalate rather than trying to resolve confidential investigations themselves. Second-line financial-crime compliance sets policy, provides oversight, challenges risk decisions, supports MLRO and sanctions decisioning, and monitors control effectiveness. Internal audit independently tests design and operation.
Regional hubs can improve consistency, but accountability must remain clear. A central investigator can prepare analysis for a Saudi or UAE case, yet the legal entity’s authorised decision maker may still own the reporting decision. Outsourcing work does not outsource statutory responsibility.
Boards and senior management need more than alert counts. Useful management information includes high-risk customer populations, overdue reviews, alert ageing, cases approaching reporting or sanctions deadlines, screening backlog, data-quality defects, repeat false positives, regulatory requests, quality-assurance findings, model/scenario changes and unresolved policy conflicts. Metrics should be split by legal entity where necessary so a strong regional average does not hide a weak local control.
What commonly fails
A recurring failure is country-level configuration without entity-level configuration. The bank knows the customer is in the UAE but does not distinguish whether the relevant entity is CBUAE-regulated, DIFC or ADGM. Procedures then point to the wrong regulator or approval route.
Another is copying thresholds and deadlines from old training material. Rules change. The UAE’s 2025 federal AML law is a clear example; using a 2018-only legal inventory in 2026 can create stale requirements. Regulatory change must update the obligation register, procedure, system rule, training and test evidence together.
A third failure is generic regional typologies. Labels such as “Middle East risk” are analytically weak and can create unfair customer outcomes. Detection should be based on product, customer, transaction, counterparty, ownership and behavioural evidence. Geography can be one factor, not a substitute for analysis.
A fourth is poor separation of sanctions and AML case logic. A transaction can be legally prohibited without being suspicious in the AML sense, and suspicious without involving a sanctioned party. Systems should permit linked cases while preserving distinct decision types.
A fifth is centralisation without data-governance design. Regional teams may need shared information, but access and cross-border transfer have to follow applicable privacy, secrecy, regulatory and group requirements. “Financial crime purpose” should not be treated as an automatic permission for unlimited replication.
BA, architecture and testing considerations
A business analyst should start with an obligation-to-control matrix. For each legal entity, map regulator, FIU, AML/CFT law, sanctions/TFS sources, licence, customer types, products, required controls, reporting routes, ownership roles, evidence and retention. Requirements can then be written against explicit obligations rather than regional assumptions.
Architecture should keep common capabilities reusable: customer master data, screening engine, monitoring platform, case tooling, list ingestion, policy/version service and management-information layer. Local behaviour should be configuration where practical: reporting forms, regulator notifications, approval roles, list scope, procedure links, disclosure restrictions and external endpoints. Hard-coding a country workflow into application logic makes regulatory change unnecessarily expensive.
Testing should include positive, negative and failure-mode scenarios. Positive tests prove true matches, suspicious patterns and reporting triggers reach the right queue. Negative tests prove ordinary remittances, trade flows and legitimate high-value customers are not systematically blocked. Failure tests cover unavailable list feeds, delayed payment data, broken customer enrichment, duplicate alerts, inaccessible FIU portals and incorrect entity routing.
Regression testing is essential after regulatory change. A UAE update should not accidentally alter Saudi reporting logic. A new sanctions list parser should not remove Arabic names or transliteration variants. A case-platform permission change should not expose FIU reports to relationship managers. Test evidence should be retained in a way that internal audit and supervisors can understand later.
Mini case: one customer, three legal questions
Consider a UAE-incorporated trading company banking with a CBUAE-regulated institution. The company has a long history of legitimate industrial imports. A new payment instruction sends a large amount to a supplier through a correspondent route, while trade documents show a newly introduced intermediary and a different transshipment port. One director’s name also produces a fuzzy sanctions-screening match.
The bank should not jump directly to “sanctions evasion.” The screening team first resolves the director identity using date of birth, nationality and other reliable identifiers. If it is a false name match, that branch of the investigation can close with evidence.
The trade and AML questions remain. Investigators compare the new transaction with the customer’s established business, review the commercial reason for the intermediary, examine invoice and shipping information available to the bank, assess the route, consider beneficial ownership and look for unexplained payment splitting or circularity. A customer explanation is evidence but not automatically proof; independent corroboration may be needed.
If the facts create reasonable suspicion under the applicable UAE framework, the authorised team considers reporting to the UAE FIU through goAML. Separately, if a targeted-financial-sanctions issue is identified, the bank follows the relevant TFS action and reporting process. If neither legal threshold is met but the activity materially changes the customer profile, the relationship may still require event-driven review, risk-rating change or enhanced monitoring.
For technology teams, the case proves why one financialCrimeStatus field is inadequate. The record may contain a sanctions match outcome of false positive, an AML investigation outcome of external report filed, a customer-risk outcome of increased risk rating and an operational payment outcome determined under policy. Each needs its own evidence and timestamp.
The operating principle to keep
The GCC is a connected banking region, but it is not one financial-crime jurisdiction. The strongest operating model uses common technology, data standards, risk methods and quality controls while preserving local legal interpretation, local statutory decisioning and regulator/FIU-specific workflows.
That balance gives a global bank the benefits of scale without sacrificing legal precision. It also gives investigators and operations teams something practical: one consistent way to think about risk, with enough local detail to make the right decision for the right entity at the right time.
Deep dive: translating a group standard into GCC legal-entity controls
The difficult part of a regional financial-crime programme is rarely writing the group policy. The difficult part is proving that each legal entity has converted that policy into the correct local procedure, system rule, decision right and regulatory action. A useful implementation method is to work from an obligation register rather than from country summaries.
For every obligation, record the source, jurisdiction, regulated entity, effective date, responsible owner, affected products, control objective, implementation mechanism, evidence and review cycle. The source might be a law, implementing regulation, central-bank rulebook, FIU instruction, sanctions notice or regulator guidance. The same control can satisfy several obligations, but the mapping should remain visible. If a screening engine supports UAE, Saudi and Qatar entities, for example, each entity should still have its own traceable legal basis and configured list scope.
This approach is especially useful when rules change. The UAE replaced its federal AML framework with Federal Decree-Law No. 10 of 2025 and Cabinet Decision 134/2025. A bank that manages change only through policy wording can miss operational dependencies. The change inventory should ask whether customer-risk models, beneficial-ownership procedures, sanctions controls, reporting forms, training, case access, record retention or quality assurance need modification. An effective-date field should then control when the new requirement applies.
Legal entity is a control attribute, not an accounting detail
Global banks often design transaction systems around products and booking centres while financial-crime systems are fed a simplified country code. That is dangerous. A customer relationship may be originated in one jurisdiction, booked in another entity and serviced by a regional hub. The legal entity responsible for the relationship or transaction determines which supervisor, FIU and local procedure may apply.
A practical data model should therefore carry at least legalEntityId, branchId, bookingLocation, licenceType, primarySupervisor, localMLRO, localFIU, sanctionsPolicySet and procedureVersion. Those fields should be available to screening, transaction monitoring and case management, not stored only in a finance master table.
Where one case spans several entities, the platform can create a parent investigation and separate legal-entity decisions beneath it. This avoids duplicating every piece of evidence while preserving independent statutory decisions. One entity may file an external report while another concludes that it has no reportable nexus. The shared facts can be common; the legal conclusions remain separate.
Supervisory perimeter matters inside a country
The UAE and Qatar demonstrate why “country = regulator” is an inadequate assumption. A UAE bank under CBUAE supervision, a DIFC firm under DFSA supervision and an ADGM firm under FSRA supervision operate within the same state but have different rulebooks and supervisory interactions. Federal AML legislation remains important across the UAE, while the financial-free-zone regulators add their own rules and notification expectations.
The same principle applies in Qatar. QCB regulates its supervised financial institutions, while QFCRA regulates authorised firms in or from the Qatar Financial Centre. QFCRA states that its AML/CFT framework is underpinned by Qatar’s national AML law, and its forms show that a QFC firm making an STR to QFIU may also have a regulatory notification obligation to QFCRA.
For delivery teams, this means a workflow selector should not be based solely on ISO country. It should resolve the regulated entity and licence. A user interface should make that visible so an investigator can see why a particular approval route or regulator notification appeared.
Suspicion reporting: preserve the decision, not just the form
FIU reporting systems are often treated as document-generation tools. In reality the defensible object is the decision record. It should contain the suspicion narrative, supporting transactions, customer information, linked parties, investigator analysis, approver, filing timestamp, external reference and any later FIU requests.
The external report itself should be immutable once filed. If the investigator discovers more information later, the case can be updated and a supplementary filing can be made according to local procedures, but the original submission should remain reconstructable.
Saudi guidance illustrates the importance of this discipline. SAMA requires procedures for internal reporting, investigation, external reporting and confidentiality; it also expects decisions not to report an internal suspicion to be documented with reasons. That requirement turns “no filing” from an absence of action into an auditable judgment.
Qatar provides another useful pattern. A QFC firm may need to notify QFCRA when it makes an STR to QFIU. The operational design should therefore have two linked tasks with separate recipients and access rules. Sending the FIU narrative to the supervisor merely because both actions arise from the same case could disclose more information than the regulatory notification requires.
UAE goAML reporting similarly benefits from structured integration. The UAE FIU’s published guidance distinguishes report and transaction information and uses FIU reference numbers for follow-up. The bank should capture those external identifiers in the case rather than relying on screenshots or analyst email folders.
Arabic names, transliteration and identity resolution
Name screening in the region can involve Arabic and Latin-script representations, patronymics, multiple family-name components, spacing differences and transliteration variants. The control problem is not solved by simply lowering a fuzzy-match threshold. That can increase false positives without improving identity resolution.
A better model separates candidate generation from adjudication. The screening engine should generate plausible candidates using names and aliases, but the decision process should compare stronger identifiers such as date of birth, nationality, passport or national ID where lawfully available, address, entity registration data, ownership and other list attributes. The system should preserve both the original script and any normalised/transliterated forms so investigators can reconstruct why a candidate matched.
Testing should include realistic Arabic/Latin variants, reordered name components, abbreviations, typographical errors and common-name collisions. Test data must be controlled and non-production where possible. The goal is not maximum alert volume; it is reliable detection with explainable disposition.
Regional trade flows and transshipment
The Gulf is deeply connected to international trade. Ports, logistics centres, free zones, commodity trading and re-export activity are legitimate economic features. Financial-crime controls should therefore avoid simplistic rules such as “free zone = high risk” or “transshipment = suspicious.” Such rules generate noise and unfair customer outcomes.
The correct question is whether the commercial and payment story is coherent. A bank can compare the customer’s declared business with the goods, counterparties, payment corridors and transaction values it observes. In trade-finance products, additional documents may allow checks on buyer, seller, consignee, vessel, port, invoice, bill of lading and goods description. In an ordinary credit transfer, most of those fields may not exist. Monitoring design must respect that difference.
CBUAE’s in-force guidance on trade-based money laundering and transshipment, effective in November 2025, is particularly useful because it explicitly connects trade-based financial crime with ML, TF, proliferation financing, sanctions and illicit transshipment. For a bank operating regionally, the guidance can inform a common risk framework while the legal implementation remains entity-specific.
Correspondent and nested relationships
GCC institutions may act as correspondents for regional banks, exchange houses, remitters or other financial institutions. The relationship risk is not defined by nationality; it depends on the respondent’s ownership, regulatory status, customer base, products, downstream access, controls and observed transaction profile.
A correspondent due-diligence file should therefore capture what services are provided, which respondent customers can access them, expected volumes and corridors, whether nested relationships are permitted, sanctions exposure and escalation contacts. Monitoring can then compare actual flows with that baseline. A sudden increase in payments through previously unseen intermediaries is meaningful only because it deviates from the understood relationship.
Where information is missing, an RFI process should be governed. Requests should be proportionate, time-bound and tracked. Repeated inability to explain material activity may change the relationship risk even if no individual transaction proves wrongdoing.
Group sanctions policy versus local law
International banks frequently apply sanctions regimes beyond those directly imposed by the host country because of their home jurisdiction, currency clearing, group policy or risk appetite. That can be lawful and prudent, but communication must be accurate.
A case disposition should distinguish at least LOCAL_LEGAL_PROHIBITION, OTHER_APPLICABLE_LEGAL_PROHIBITION, GROUP_POLICY_RESTRICTION, POTENTIAL_MATCH, and NO_RESTRICTION. Customer-facing explanations may be constrained by law and policy, but internal records should preserve the actual basis. Otherwise management information can misstate policy exits as local sanctions breaches.
The same distinction helps change management. A UN designation implemented through local law may require immediate freezing, while a group-risk policy change may require controlled offboarding rather than a legal freeze. Conflating those outcomes can create both legal and customer harm.
Control effectiveness is measured by outcomes
Regional dashboards often focus on volumes: alerts generated, cases closed, STRs filed and customers screened. Those are workload indicators, not proof of effectiveness.
Better measures include overdue-alert risk, time to disposition for urgent sanctions cases, percentage of cases with complete legal-entity mapping, data-quality exceptions affecting screening, repeat false-positive drivers, FIU feedback themes, scenario coverage gaps, overdue KYC refreshes, sanctions-list ingestion timeliness, quality-assurance error rates and remediation ageing.
Metrics should be segmented by entity and product. A regional average can look healthy while a small entity has an unmanageable backlog or broken data feed. Senior management needs to see both the regional control and the local weak point.
What an examiner or internal auditor should be able to reconstruct
For a sample case, a reviewer should be able to move from the customer and transaction to the applicable obligation, data used, alert logic, investigator analysis, approval, reporting or sanctions action and final customer/payment outcome. They should also be able to see which policy and procedure versions were effective on that date.
That end-to-end traceability is the best test of whether the regional operating model is real. If teams can explain the policy but cannot reconstruct an actual decision, the framework is documentation rather than control.
Advanced practice: requirements, controls and testable acceptance criteria
A regional financial-crime programme becomes dependable when legal interpretation can be translated into testable delivery requirements. The following examples show how a business analyst can convert broad AML/CFT expectations into system behaviour without hard-coding legal conclusions that belong to compliance or legal teams.
Requirement pattern 1: legal-entity routing
A weak requirement says: “The system shall support GCC regulations.” That cannot be tested meaningfully. A stronger requirement says that every customer, transaction, screening alert and investigation must resolve to the responsible legal entity before a regulatory workflow can be selected. The entity record must identify the primary supervisor, FIU/reporting destination, configured sanctions/TFS regime, responsible MLRO or authorised decision role, and effective procedure version.
Acceptance testing should prove that otherwise identical alerts route differently where the regulated entity differs. A UAE onshore case must not be sent to a DIFC-specific notification queue merely because the customer address is Dubai. A QFC case must not lose a QFCRA notification task when an STR is filed to QFIU. A Saudi case must resolve to the Saudi FIU workflow rather than a generic regional mailbox.
Failure handling matters as much as the happy path. If the legal entity cannot be resolved, the platform should stop the external-reporting action and raise a controlled data-quality exception. Guessing a jurisdiction from an IBAN prefix or customer country is not an acceptable fallback for statutory reporting.
Requirement pattern 2: sanctions disposition with legal basis
A sanctions decision should require the reviewer to record the matched party, list source, match confidence or resolution evidence, applicable legal or policy regime, ownership/control assessment where relevant, action and approver. The system should not permit a confirmed-match disposition without a basis explaining why the list entry applies to the party being reviewed.
For time-sensitive true matches, the workflow should support urgent escalation without bypassing auditability. A fast decision still needs a timestamp, accountable reviewer and evidence. Where the local TFS framework requires freezing without delay, latency must be measured from the point the institution has the relevant confirmed information, not from when a weekly operations report is produced.
Negative testing should include common-name matches, transliteration variants and companies with similar trading names. A false positive should close only after identity resolution, not merely because an analyst recognises the customer.
Requirement pattern 3: suspicious-reporting confidentiality
FIU reports should be held in a restricted security domain. Relationship managers, customer-service teams and most operations users normally need a safe operational status, not the report narrative or even confirmation that an external report was made where disclosure could create tipping-off risk.
An acceptance test can create a case, file a simulated STR and then verify access from several roles. The MLRO and authorised investigator may see the full report. A relationship manager may see only that compliance review is complete or that a transaction remains under review, according to approved policy. System administrators should not gain business access merely because they maintain the platform; privileged-access monitoring should cover exceptional technical access.
Requirement pattern 4: regulatory change effective dating
Every material control change should have an effective date and traceable source. If a rule changes on 1 April, transactions before and after that date may legitimately be evaluated under different procedure versions. The case record should therefore store the version applied at decision time rather than dynamically displaying today’s policy against an old case.
Testing should include future-dated rule deployment, rollback before effective date, emergency implementation, and retrospective reconstruction. A release that updates the user interface but leaves an old rule in a batch-screening service is an incomplete regulatory change.
Scenario design: remittance and exchange-house relationships
Consider a bank providing settlement services to a licensed exchange house. The customer has large volumes of low-value remittances across several corridors. A simplistic threshold scenario will generate constant noise. Better monitoring begins with the respondent or customer profile: expected corridors, settlement accounts, transaction volumes, agent relationships and customer segments.
Useful signals might include a material change in corridor mix, unexpected high-value concentration, rapid movement through new intermediaries, unexplained funding from third parties, use of accounts inconsistent with the approved settlement model, or repeated activity involving counterparties outside the stated business. Each signal should be combined with profile and network context before investigators infer suspicion.
Testing needs legitimate high-volume samples as well as suspicious patterns. If the system can detect only abnormal activity by flagging nearly every remittance, the control is not effective.
Scenario design: trade and re-export activity
A trading company operating from a free zone starts paying a new supplier in one country while goods are shipped through a different port to a customer in a third country. This can be completely legitimate. The detection objective is not to punish multi-country trade but to identify material inconsistencies.
Where data are available, the bank may compare invoice value with payment value, goods description with the customer’s business, buyer/seller relationships, unusual changes in routing, repeated document amendments, unexplained third-party payments and relevant sanctions or export-control indicators. The bank should record data provenance. A vessel identifier obtained from a trade document is stronger evidence than a name inferred from a short payment narrative.
A test pack should contain ordinary transshipment cases so the rule does not equate route complexity with wrongdoing. It should also include cases where several individually weak signals combine into a stronger investigation rationale.
Scenario design: private-bank source of wealth
A long-standing private-banking customer receives proceeds from the sale of a family business and transfers funds into an investment vehicle. Large value alone is not suspicious. The control question is whether the transaction fits the documented source of wealth and source of funds.
The review might use audited financial statements, sale agreements, public corporate records, tax or legal documentation where appropriate, banking history and ownership information. A good case record explains why evidence is credible rather than merely listing documents received.
Testing should include changes in ownership, partial sale proceeds, multi-currency settlement and transfers through legitimate advisers. The system should permit nuanced conclusions such as “source verified, profile updated” rather than forcing binary suspicious/not-suspicious labels too early.
Data-quality controls deserve their own alerts
A financial-crime engine is only as reliable as its inputs. Missing date of birth can weaken sanctions resolution. Truncated beneficiary names can weaken screening. Lost legal-entity identifiers can misroute cases. A regional programme should therefore monitor data quality as a control in its own right.
For each critical field, define source, transformation, mandatory/conditional status, completeness target and failure owner. Reconciliation should compare record counts and key identifiers across channel, payment hub, screening engine and case platform. A technically successful message transfer is not enough if a field silently becomes blank.
Model and scenario governance
Machine-learning or advanced analytics can support anomaly detection, network analysis and prioritisation, but the legal decision still needs explainable evidence. Model governance should document purpose, training/validation data, limitations, performance, bias risks, change control and human oversight.
Regional data can improve detection where sharing is lawful, but differences in product mix and customer behaviour matter. A model trained mainly on retail payments in one market may perform poorly on corporate trade activity in another. Performance should therefore be monitored by relevant segment and entity rather than only at portfolio level.
Operational resilience
FIU portals, sanctions feeds, case platforms and screening services can fail. Business-continuity procedures should specify what happens when each critical dependency is unavailable. For sanctions screening, degraded operation may be unacceptable for certain flows; for transaction monitoring, delayed post-event processing may be possible if the backlog is controlled. These are risk decisions that must be agreed before an incident.
Tests should simulate list-feed failure, case-platform outage, duplicate report submission, delayed batch files and loss of an enrichment provider. Recovery should prove that no transactions or cases are silently dropped and that timestamps remain accurate.
The acceptance test that matters most
Select one real-world style customer journey and trace it end to end: onboarding, risk rating, screening, payments, monitoring, alert, investigation, legal-entity decision, FIU or sanctions action, customer outcome and management information. If the team cannot explain every hand-off, field and accountable owner, the control is not yet ready for production.
Practice close: what good looks like
Before calling a GCC financial-crime control complete, test whether the team can answer a short set of practical questions from evidence rather than memory.
For a customer or transaction, can the platform identify the responsible legal entity, licence and supervisor? Can an investigator see which local AML/CFT procedure and sanctions/TFS policy version applied on the decision date? If an external report is considered, does the workflow resolve the correct FIU and authorised decision maker rather than infer them from customer country alone?
For screening, can the bank show the list version, candidate data, identity-resolution evidence and legal or policy basis for the final action? For transaction monitoring, can it prove that the scenario received the necessary customer and payment data and that missing fields are visible as data-quality issues? For cross-entity investigations, can teams share permitted evidence while keeping FIU reports and sensitive law-enforcement information restricted?
For change management, take a recent legal or rulebook amendment and trace it from source to impact assessment, policy, procedure, system configuration, training, testing and production evidence. If any link is missing, the regulatory-change process is incomplete.
For operational resilience, simulate a sanctions-feed failure, an unavailable case platform and an external-reporting portal outage. Confirm that the institution has an approved fallback, preserves the backlog, avoids silent loss and can reconstruct the incident afterward.
Finally, review management information by legal entity. A healthy regional average should not hide overdue cases, broken feeds or weak quality results in a smaller market. The goal is a common regional control framework with locally correct decisions, not a common dashboard that conceals local accountability.
A chapter-level review should reach the same conclusion: every legal claim, workflow and diagram must resolve to current authoritative evidence or be framed explicitly as bank design practice rather than law.
Masterclass: a regional case without a regional shortcut
A banking group has three relevant entities: a CBUAE-regulated bank in the UAE, an authorised firm in the Qatar Financial Centre, and a Saudi bank. A corporate customer is onboarded by the UAE entity. The customer imports industrial equipment and uses the UAE account for supplier payments. Its beneficial owners are well documented, the business has operated for eight years and historic activity is consistent with the stated profile.
The customer now requests a payment to a new supplier. The instruction originates in the UAE, but the beneficiary account is at the group’s Saudi entity. The invoice names an intermediary in Qatar and refers to re-export through a regional logistics hub. At the same time, the beneficiary company’s director generates a possible sanctions match because the name resembles a listed person.
A weak regional design would create one “GCC alert”, ask a central investigator to decide whether it is suspicious and then apply the result everywhere. A stronger design separates shared evidence from local legal decisions.
The screening team first resolves the sanctions candidate. The listed person has a different date of birth and nationality, and the beneficiary director’s government-issued identifiers match the bank’s verified KYC record. The potential sanctions match is therefore closed as a false positive with the identity-resolution evidence preserved. No one should continue calling the payment a “sanctions case” merely because screening originally triggered.
The trade pattern still merits review. The UAE investigator compares the customer’s historic suppliers and goods with the current invoice, checks why an intermediary has appeared, verifies the commercial relationship and reviews the payment route. The intermediary is a logistics coordinator, not a recipient of funds. The customer provides a contract showing that the supplier changed because the previous manufacturer could not meet delivery dates. Public corporate records and the bank’s own counterparty data support the supplier’s stated activity.
The goods are within the customer’s normal industrial category. The bank has no evidence that they are controlled items, and it does not pretend to make an export-classification decision from a vague invoice description. However, because the routing changed materially, the investigator checks the jurisdictions, parties and available shipping information against the bank’s sanctions and trade-risk controls.
The Saudi entity has a different question. It banks the beneficiary and sees an incoming payment from a UAE customer. Its own customer profile describes the beneficiary as an industrial-equipment manufacturer with expected Gulf exports. The incoming transaction is therefore broadly consistent with the Saudi customer’s expected activity. SAMA monitoring requirements still apply to the Saudi relationship, but the existence of a UAE review does not automatically create Saudi suspicion.
The Qatar intermediary is not a customer of the group’s QFC entity, so the QFC entity has no direct transaction or customer relationship in this example. The central case platform can record that the intermediary was reviewed as part of the UAE investigation, but it should not invent a Qatari STR workflow merely because a Qatari company appears in a document. Legal nexus must come from actual obligations and facts.
The UAE investigator concludes that the transaction is unusual compared with the customer’s recent history but is reasonably explained and corroborated. No UAE STR is filed. The event does, however, trigger an update to expected supplier geography and a relationship note because the customer’s sourcing model has changed. The Saudi entity closes its own monitoring alert as consistent with expected beneficiary activity.
Now change one fact. Suppose independent evidence shows that the Qatar intermediary is secretly controlled by an owner previously undisclosed by the UAE customer, and funds are being split through several related companies before reaching the supplier. The same transaction now raises much stronger questions about ownership transparency, economic purpose and layering. The UAE entity may form suspicion and follow its UAE FIU reporting procedure. The Saudi entity must separately assess what its own customer knew and whether the beneficiary relationship or incoming funds create reasonable grounds for suspicion under Saudi requirements.
Even then, the group should not replace two statutory assessments with one global conclusion. The central investigation can share lawfully available evidence and coordinate risk understanding. Each accountable entity still records its own decision, filing status, regulator/FIU route and customer outcome.
The case demonstrates four lessons. First, an alert is a question, not a verdict. Second, shared evidence does not erase local accountability. Third, a party’s location is not the same as a legal reporting nexus. Fourth, customer-profile maintenance is a control outcome even when no external report is filed.
For testers, this case is ideal as an end-to-end scenario. It checks identity resolution, legal-entity routing, cross-entity case linking, restricted FIU-report access, customer-profile updates and management information. A robust platform should pass all of those without using one undifferentiated “GCC compliance” status.
References and further reading
Global standard
- Financial Action Task Force, The FATF Recommendations and June 2026 update to Recommendation 6 on targeted financial sanctions and humanitarian exemptions: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/update-recommendation-6-june-2026.html
United Arab Emirates
- Central Bank of the UAE, AML/CFT Supervision, including the current federal AML/CFT legal framework and supervisory material: https://centralbank.ae/en/our-operations/anti-money-laundering-aml/
- CBUAE Rulebook, Federal Decree by Law No. 10 of 2025 Regarding Anti-Money Laundering and Combating the Financing of Terrorism and Proliferation Financing: https://rulebook.centralbank.ae/en/rulebook/federal-decree-law-no-10-2025-regarding-anti-money-laundering-and-combating-financing
- Central Bank of the UAE, Targeted Financial Sanctions, TFS Guidance and CBUAE Supervision: https://centralbank.ae/en/our-operations/anti-money-laundering-aml/targeted-financial-sanctionss/
- CBUAE Rulebook, Guidance for Licensed Financial Institutions on Risks Related to Trade-Based Money Laundering and Transshipment, effective 7 November 2025: https://rulebook.centralbank.ae/en/entiresection/6788
- UAE Financial Intelligence Unit, goAML launch portal and registration/reporting access: https://services.uaefiu.gov.ae/sacm/
- Dubai Financial Services Authority, February 2026 amendments aligning the AML module with Federal AML legislation: https://www.dfsa.ae/news/notice-amendments-legislation-february-2026
- Abu Dhabi Global Market FSRA, May 2026 enhancements to the AML framework: https://www.adgm.com/media/announcements/adgm-fsra-finalises-enhancements-to-its-anti-money-laundering-framework
Saudi Arabia
- Saudi Central Bank Rulebook, The Anti-Money Laundering and Counter-Terrorism Financing Guide: https://rulebook.sama.gov.sa/en/anti-money-laundering-and-counter-terrorism-financing-amlctf-guide
- Saudi Central Bank Rulebook, Section 7: Monitoring of Transactions and Activities: https://rulebook.sama.gov.sa/en/section-7-monitoring-transactions-and-activities
- Saudi Central Bank Rulebook, Section 8: Reporting of Suspicious Transactions: https://rulebook.sama.gov.sa/en/section-8-reporting-suspicious-transactions
- Saudi Central Bank Rulebook, Guidance on Assessing Business Risks Related to Money Laundering, Terrorist Financing and Proliferation Financing, 31 December 2025: https://rulebook.sama.gov.sa/en/circular-re-guidance-assessing-business-risks-related-money-laundering-terrorist-financing-and
Qatar
- Qatar Central Bank, Instructions to Banks, including AML/CFT supervision and control: https://www.qcb.gov.qa/en/Pages/InstructionsToBanks.aspx
- Qatar Financial Information Unit, official site and publications, including AML/CFT Law No. 20 of 2019 and STR guidance: https://www.qfiu.gov.qa/
- Qatar Financial Centre Regulatory Authority, AML/CFT Regulatory Framework: https://www.qfcra.com/aml-cft-regulatory-framework/
- Qatar Financial Centre Regulatory Authority, AML/CFT forms and QFIU/QFCRA reporting notifications: https://www.qfcra.com/aml-cft-forms/
Bahrain, Oman and Kuwait
- Central Bank of Bahrain, Rulebook Volume 1 for Conventional Banks, Financial Crime module. CBB publishes separate rulebook volumes for different licence categories, so institutions should use the volume applicable to their licence: https://www.cbb.gov.bh/wp-content/uploads/2023/06/Vol-1_FC_2023.pdf
- Central Bank of Oman, Law on Combating Money Laundering and Terrorism Financing and supervisory instructions: https://cbo.gov.om/Pages/AntiMoneyLaunderingLaw.aspx
- Central Bank of Oman, AML/CFT supervisory framework: https://cbo.gov.om/pages/antimoneylaundering.aspx
- Central Bank of Oman, Banking Law, including Royal Decree 2/2025 replacing the previous Banking Law: https://cbo.gov.om/Pages/BankingLaw.aspx
- Central Bank of Kuwait, AML/CFT supervisory communication for banks and exchange companies: https://www.cbk.gov.kw/en/cbk-news/announcements-and-press-releases/press-releases/2023/03/202303201500-cbk-organizes-amlcft-workshops
- Kuwait Financial Intelligence Unit, official mandate and Law No. 106 of 2013 basis: https://www.kwfiu.gov.kw/en/aboutus
These sources should be rechecked when applying the chapter to a live customer, transaction or control change. Regulatory rulebooks, sanctions measures, reporting forms and supervisory expectations can change after the chapter review date.