The FATF Framework The Common Architecture
Before examining national requirements, it is useful to understand the international framework that underpins all six GCC states’ CDD regimes. The FATF Recommendations, particularly Recommendations 10, 12 and 17, set out the global standard for customer due diligence.
FATF Recommendation 10 requires financial institutions to conduct CDD when establishing business relationships, when carrying out occasional transactions above specified thresholds, when there is suspicion of money laundering or terrorist financing, or when there is doubt about the veracity or adequacy of previously obtained customer identification data.
FATF Recommendation 12 addresses the requirements for conducting enhanced due diligence on politically exposed persons (PEPs), requiring financial institutions to have appropriate risk management systems to determine whether a customer or beneficial owner is a PEP, to obtain senior management approval to establish the relationship, to take reasonable measures to establish the source of wealth and source of funds, and to conduct enhanced ongoing monitoring.
FATF Recommendation 17 requires financial institutions to implement enhanced due diligence for higher-risk customers, business relationships or transactions.
These FATF standards inform the CDD requirements of all six GCC states, though the precise implementation, supervisory rigour and enforcement intensity vary considerably across jurisdictions.
Saudi Arabia SAMA CDD Requirements
The Saudi Arabian Monetary Agency (SAMA) AML/CFT Guidelines establish the customer due diligence framework for Saudi Arabia’s financial institutions. SAMA requires that banks and finance companies apply CDD measures when establishing business relationships, including identifying the customer and verifying identity using reliable, independent documents, data or information.
SAMA’s framework adopts a risk-based approach to CDD, requiring institutions to classify customers according to risk categories and apply simplified, standard or enhanced due diligence accordingly. Higher-risk customers, including PEPs and customers from jurisdictions identified as higher-risk, require enhanced due diligence.
Beneficial ownership verification is a key element of SAMA’s CDD requirements. Institutions are required to identify the beneficial owner of legal persons and take reasonable measures to understand the ownership and control structure of those entities. SAMA has communicated particular expectations around the identification of nominal shareholders and the verification of complex ownership structures.
Saudi Arabia underwent its FATF mutual evaluation review, which identified some areas of CDD implementation that required strengthening, particularly around the quality of beneficial ownership information and the consistency of risk-based application of CDD across the financial sector. Compliance teams at Saudi institutions should ensure their CDD programmes reflect not only SAMA’s minimum requirements but also the direction of supervisory expectations emerging from the FATF evaluation process.
UAE Central Bank CDD Requirements
The UAE’s AML/CTF framework centres on Federal Law No. 20/2018 on Anti-Money Laundering, supplemented by Cabinet Decision No. 10/2019 on Anti-Money Laundering and Combating the Financing of Terrorism. The Cabinet Decision provides detailed requirements for CDD that the UAE Central Bank has incorporated into its regulatory framework for licensed financial institutions.
Under the UAE framework, CDD requirements include identifying the customer and verifying identity through reliable and independent documents, identifying the beneficial owner and taking risk-based measures to verify their identity, understanding and obtaining information on the purpose and intended nature of the business relationship, and conducting ongoing due diligence through monitoring transactions and updating customer data.
The UAE’s approach to beneficial ownership has been shaped significantly by both domestic regulatory requirements and international expectations, particularly from FATF evaluations. UAE financial institutions are required to identify natural persons who own more than a specified percentage of a legal entity, and to understand the full ownership and control structure. Cabinet Decision No. 10/2019 also introduced obligations around understanding the purpose of accounts and relationships, which has implications for how UAE banks structure their onboarding conversations.
The UAE has also developed expectations around biometric KYC and remote onboarding, driven partly by the growth of digital banking in the Emirates and partly by the UAE Central Bank’s engagement with financial technology providers. Institutions offering digital onboarding must ensure that remote identity verification meets the standards expected by the Central Bank, including the use of reliable biometric and documentary verification methods.
Qatar QCB AML/CFT Instructions on CDD
The Qatar Central Bank (QCB) AML/CFT Instructions establish CDD obligations for Qatari financial institutions. The QCB framework requires identification and verification of customer identity, identification and verification of beneficial ownership, assessment of the purpose and nature of the business relationship, and ongoing monitoring.
Qatar’s CDD framework aligns with FATF Recommendations and incorporates a risk-based approach, requiring financial institutions to assess the risk posed by each customer and apply due diligence proportionate to that risk. Enhanced due diligence is required for higher-risk categories including PEPs and customers from higher-risk jurisdictions.
Qatar underwent a FATF mutual evaluation process in which CDD implementation was examined in detail. The findings identified areas of strength and areas requiring development, including the consistency with which CDD is applied across the Qatari financial sector and the quality of beneficial ownership information held by Qatari institutions.
For compliance professionals managing Qatari operations, the QCB’s expectations around ongoing CDD are particularly relevant. The obligation to keep customer information current and to conduct periodic reviews of customer risk ratings is not a one-time onboarding function but an ongoing compliance obligation that requires sustained operational resources.
Kuwait CBK CDD Module
The Central Bank of Kuwait (CBK) AML/CFT Module establishes comprehensive CDD requirements for Kuwaiti financial institutions. The CBK framework requires identification of customers, verification of identity through reliable documents or data, identification of beneficial owners, understanding of the nature and purpose of the business relationship, and ongoing monitoring.
The CBK adopts a risk-based approach to CDD, with simplified CDD available for lower-risk customers and enhanced due diligence required for higher-risk categories. PEPs require senior management approval and enhanced ongoing monitoring under the CBK framework.
Kuwait’s FATF mutual evaluation identified some areas of concern regarding the implementation of CDD requirements across the Kuwaiti financial sector, including the quality of beneficial ownership information and the consistency of risk-based application of due diligence by smaller financial institutions. For compliance teams, this means that a strong CDD programme is not only a regulatory requirement but also a demonstration of compliance quality that matters in supervisory examinations.
Oman CBO CDD Regulation
The Central Bank of Oman (CBO) AML/CFT Regulation establishes CDD requirements for Omani financial institutions. The CBO requires customer identification and verification, beneficial ownership identification and verification, understanding of the purpose and nature of the business relationship, and ongoing monitoring.
Oman’s CDD framework incorporates a risk-based approach, with the CBO expecting institutions to categorise customers according to risk and apply due diligence proportionate to the assessed risk. Enhanced due diligence requirements apply to higher-risk customer categories, including PEPs and higher-risk jurisdictions.
Oman’s FATF mutual evaluation process identified CDD as an area requiring continued supervisory attention, noting that while the regulatory framework was broadly in place, the consistency of implementation across the Omani financial sector varied. Compliance teams at Omani institutions should ensure their CDD policies and procedures are documented, consistently applied and supported by adequate training.
Bahrain CBB AML Module CDD Requirements
The Central Bank of Bahrain (CBB) AML Module is regarded as one of the more developed regulatory frameworks in the GCC. The CBB requires financial institutions to apply CDD measures that include identifying the customer and verifying identity, identifying the beneficial owner, assessing the purpose and intended nature of the business relationship, and conducting ongoing monitoring.
The CBB’s risk-based approach requires Bahraini financial institutions to categorise customers according to risk and apply due diligence proportionate to the risk assessment. Enhanced due diligence applies to higher-risk categories, and the CBB has published specific guidance on the factors that should inform risk assessments.
Bahrain’s CDD framework has been shaped by its role as a regional financial centre, with Bahraini institutions serving customers from across the Gulf and beyond. This international customer base creates particular challenges around beneficial ownership verification and the assessment of risk associated with customers from jurisdictions with different regulatory standards.
Beneficial Ownership Across the GCC
Beneficial ownership verification is one of the areas where GCC CDD requirements have evolved most significantly in recent years, driven by FATF mutual evaluation findings, international pressure and domestic regulatory reforms.
All six GCC states now require financial institutions to identify the natural person or persons who ultimately own or control a legal entity, with thresholds typically set at 25 percent ownership or control. However, the quality of beneficial ownership information available to GCC financial institutions varies, and compliance teams frequently encounter challenges in verifying ownership structures in jurisdictions where corporate opacity is culturally embedded.
The UAE has been particularly active in this area, with Cabinet Decision No. 10/2019 establishing specific requirements for beneficial ownership identification and the UAE’s regulatory authorities engaging with the FATF process on beneficial ownership transparency. Bahrain’s CBB has also developed detailed expectations around beneficial ownership verification for Bahraini institutions serving international customers.
KYC Equivalence and Mutual Recognition in the GCC
A question that arises for multinational institutions operating across the GCC is whether a KYC assessment conducted in one GCC state can be relied upon in another. There is no formal mutual recognition arrangement between GCC states for KYC/CDD standards.
However, the convergence of GCC regulatory frameworks around FATF Recommendations means that the substantive requirements are broadly similar. A KYC assessment conducted under UAE regulations, for example, will address the same core elements as an assessment conducted under Qatari regulations. The practical challenge is that each jurisdiction’s regulator expects the institution’s local entity to maintain its own CDD programme and cannot fully delegate that obligation to another group entity.
For compliance leaders, this means that GCC-wide KYC programmes should be designed with a common baseline of standards that satisfies the most demanding of the six GCC frameworks, with jurisdiction-specific overlays where national requirements exceed that baseline.
Digital Onboarding and Biometric KYC in the GCC
The GCC states are at different stages of developing regulatory frameworks for digital onboarding and biometric identity verification. The UAE has been the most active in this area, with the UAE Central Bank engaging with fintech providers and issuing guidance on remote onboarding that accommodates biometric verification methods.
Saudi Arabia has also developed expectations around digital onboarding, with SAMA engaging with fintech institutions on remote KYC solutions. Qatar, Kuwait, Oman and Bahrain are at earlier stages of formalising digital onboarding requirements, though the commercial pressures driving digital adoption are present across all six states.
For compliance professionals, the key principle is that whatever onboarding method is used, whether face-to-face, digital or hybrid, it must result in the same outcome: reliable identification and verification of the customer, identification of beneficial owners, assessment of risk and establishment of ongoing monitoring.
What Compliance Leaders Should Consider
Managing KYC and CDD across the GCC requires balancing the commonality of FATF-based standards against the real differences in national implementation, supervisory expectation and enforcement intensity.
Several practical considerations follow from this analysis. First, institutions should maintain a CDD policy framework that establishes a common baseline across all GCC entities while allowing for jurisdiction-specific requirements. Second, beneficial ownership verification deserves particular attention, as it is an area where FATF mutual evaluation findings have been consistently critical across the Gulf region. Third, institutions should monitor the evolving digital KYC landscape in each GCC state, as regulatory frameworks for remote onboarding are developing rapidly. Fourth, the risk-based approach to CDD is not a one-time exercise but requires ongoing customer risk assessment and periodic review.
The ultimate objective is a GCC-wide CDD programme that satisfies the most demanding regulatory standard while enabling efficient customer onboarding and relationship management across the region.
KYC and CDD Requirements Across the GCC: A Six-State Comparison
A practical comparison of KYC and CDD requirements across all six GCC states. Understand the differences between SAMA, UAE Central Bank, QCB, CBK, CBO and CBB approaches to customer due diligence.
Speak to our teamThis article was accurate at the time of publication in August 2026 and is intended for general informational purposes only. It does not constitute legal, regulatory or compliance advice. Organisations should seek qualified professional guidance in relation to their specific obligations.




