AML/CFT screening software for the UAE, ADGM and DIFC
SonarPulse is an AML/CFT screening, risk-scoring and transaction-monitoring platform for firms in the UAE, including those licensed in ADGM and the DIFC. It is built on local data sources from the major Middle-East and African financial centres, including Abu Dhabi Global Market and the Dubai International Financial Centre.
What UAE firms are measured against
- Two layers in the free zones. ADGM firms are supervised by the FSRA and DIFC firms by the DFSA. Each centre has its own AML rulebook, and federal AML legislation applies in both. Two financial centres, two rulebooks.
- New executive regulations. Cabinet Resolution No. (134) of 2025, the Executive Regulations of Federal Decree by Law No. (10) of 2025, repealed Cabinet Decision No. (10) of 2019 and is effective from 14 December 2025. What the repeal means for your policy.
- Targeted financial sanctions within 24 hours. Under Cabinet Decision No. 74 of 2020, “without delay” means within 24 hours of the listing decision, and firms screen against the UAE Local Terrorist List as well as the UN list. Both ADGM and the DIFC point firms to the federal instrument. UN sanctions across the six.
- STRs to the UAE FIU through goAML, without delay and directly under Decree-Law 10/2025, Article 18. STR deadlines compared.
- Know your business partner. Section 9.2 of the FSRA’s AML and Sanctions Rulebook puts due diligence on counterparties that are not customers into ADGM law. Where vendor due diligence already sits.
How SonarPulse covers it
- Sanctions, PEP and adverse media across 250+ sources including the UN, OFAC, EU and UK lists, plus your own lists as per-tenant blacklists, with daily re-screening and hit-diffing so a new designation surfaces as a consolidated alert.
- Onboarding and KYB for six entity types, with UBO and shareholder hierarchy, document capture and biometric identity verification.
- TMX transaction monitoring: fraud, AML and sanctions rules in one real-time engine on an ISO 20022-aligned schema, with goAML report generation under four-eyes control.
- Vendor Verification for counterparties that are not customers: financial KPIs, document integrity and the ownership ecosystem behind the name.
- AskSonar, sourced answers across the national rulebooks of the UAE, Mauritius and Morocco, with a link to the passage every answer came from.
- Hosted where your regulator wants it: in-country cloud for screening and scoring, on-premises for TMX inside the payment perimeter.
Questions UAE compliance teams ask
Does an ADGM or DIFC firm follow federal AML law or its centre’s rulebook?
Both. The FSRA’s AML Rulebook and the DFSA’s rulebook each state that federal AML legislation applies in the centre, and a federal breach may also be evidence of a breach of the centre’s own rules.
Is the UN consolidated list enough for UAE sanctions screening?
No. The UAE applies its own Local Terrorist List, issued by the Cabinet, alongside the UN list, and the freeze clock is 24 hours from the listing decision.
Our policy still cites Cabinet Decision 10 of 2019. Is that a problem?
Yes. The CBUAE Rulebook records it as repealed. Its replacement is Cabinet Resolution No. (134) of 2025.
Further reading
Start with a compliance health check.
A working session with your compliance team, then a walkthrough against your own risk appetite: the lifecycle end to end, scoring weights set to your policy, and a review of the audit trail the system produces.