UAE KYC Digital Platform: Key Requirements and Practical Impact

On 20 April 2026, the UAE Cabinet issued Cabinet Resolution No. (55) of 2026, promulgating the Executive Regulations of Federal Decree-Law No. (30) of 2024 regarding the KYC Digital Platform, and Cabinet Resolution No. (56) of 2026 on administrative violations and sanctions. Both took effect on 21 April 2026.

The framework regulates the collection, management and use of KYC Data through the Platform. It applies to the Company, Data Providers, Customers and Users, as well as other persons covered by the Executive Regulations. This article outlines the principal data requirements, responsibilities, report-access procedures, safeguards, enforcement framework and practical implications.

Why Was the KYC Digital Platform Introduced?

The KYC Digital Platform is part of the UAE’s move towards a more integrated digital financial infrastructure. One of the practical issues identified by the Central Bank of the UAE is the duplication that can arise when customers are required to provide similar information to different institutions as part of separate due diligence processes.

The Central Bank has stated that the Platform is intended to reduce this duplication and associated compliance costs, while supporting more efficient KYC and Know Your Business (KYB) processes through automated workflows and trusted data sources. It is also intended to make digital onboarding faster and more reliable for individuals and businesses.

The Platform does not replace the separate customer due diligence and AML/CFT/PF obligations applicable to regulated entities. Rather, it provides a regulated infrastructure through which KYC information can be collected, maintained and accessed, subject to requirements relating to consent, confidentiality, data quality and security.

What Information Does the Platform Contain?

Article 3 of Resolution No. (55) of 2026 sets separate data requirements for natural persons and legal persons or arrangements.

Data Requirements for Natural Persons

For a natural-person Customer, Article 3(1) covers the name in Arabic and English; date and place of birth; valid Emirates ID and travel-document copies and particulars; residence or entry visa information; UAE and, where applicable, overseas residential address; occupation and employer; telephone and email details; principal sources of income; and, for a Politically Exposed Person (PEP), the reasons for that classification.

Data Requirements for Legal Persons and Arrangements

Article 3(2) covers the following information for legal persons, including Legal Arrangements:

  • Name in Arabic and English
  • Legal form
  • Official contact details
  • Head office and branch addresses
  • Establishment, registration or licensing status
  • Trade register and trade licence information
  • Constitutional documents
  • Relevant licences
  • Names of persons in senior management
  • Beneficial Owner details
  • Amount of capital
  • Sources of funding and income
  • Number and nominal value of shares or interests, where applicable
  • Tax Registration Number

Where the Data Provider is a Financial Institution, Article 3(3) also requires the data and documents Financial Institutions must collect and retain under Central Bank legislation and regulations. KYC Data must also include other information specified by the Central Bank or required under UAE AML/CFT/PF legislation.

Who Has Responsibilities Under the Platform?

The Platform operates through three principal categories: Data Providers, the Company and Users. Articles 11, 12 and 13 allocate responsibilities to each.

Data Providers

Data Providers may include government authorities, private-sector entities operating in the UAE or its free zones, financial institutions, insurance companies and related professions licensed by the Central Bank, and other potential data sources identified by the Company. Under Article 11, a Data Provider must provide requested KYC Data under its agreement with the Company and verify the data’s validity, source, accuracy and up-to-datedness before submission. It is not liable for unauthorised use after submission where this occurs without its knowledge, involvement or negligence.

The Company and Data Providers may also enter arrangements governing secure electronic connectivity, data sharing and timely transmission and updating of information.

The Company

Established under Article 4 of Decree-Law No. (30) of 2024, the Company manages the Platform. Its duties include protecting data against loss and unauthorised access, establishing electronic links, integrating the database with the Central Bank, retaining requests for five years, assessing data quality and handling complaints under Article 15.

Article 14 also requires technical and organisational safeguards, including encryption, access controls, activity logging and monitoring, review of access permissions and usage logs, privacy and data-use governance, periodic system audits and business continuity measures.

Platform Users

Users may obtain KYC Reports as necessary for due diligence and compliance duties. They must keep reports confidential, not transfer them or their data outside the UAE, retain copies for at least five years from issuance, and dispose of them securely only after both the purpose has been fulfilled and the retention period has expired. Users must also inform Customers of the purpose of retrieval and submit to Company audits or reviews.

How Can Customers Access or Amend KYC Reports?

Articles 6, 7 and 15 of Resolution No. (55) govern Customer access to KYC Reports, amendment of incorrect, incomplete, inaccurate or outdated data, and data-related complaints.

A Customer may request access to its own KYC Report, subject to the prescribed form, stated purpose, fees and any additional Central Bank controls; the Company must verify identity and legal capacity. Customers may request amendments to defective or outdated data. A Customer or User may also complain about data in a KYC Report, which the Company may refer to the relevant Data Provider for determination.

How Can a KYC Report Be Obtained?

Resolution No. (55) establishes two principal routes for obtaining a KYC Report.

Reports Based on Customer Consent

Under Article 4, a User may request a KYC Report with Customer Consent. The prescribed electronic request must identify the Customer, state the purpose and include proof of consent. Consent may be given in writing, digitally or by any other legally acceptable means. The Company provides the Report after verifying consent and applicable requirements and upon payment of the prescribed consideration.

Reports Relating to Indebted Customers

Article 5 allows a User to request a KYC Report without consent where a person is indebted to that User and the request is supported by an order from the judge of urgent matters. The User must attach the original order, a certified true copy or an electronically verifiable copy. The Company must verify the order and User identity and retain electronic copies of both.

What Happens If the Rules Are Breached?

Cabinet Resolution No. (56) of 2026 establishes the administrative enforcement framework for breaches of the Decree-Law, its Executive Regulations and relevant implementing Central Bank resolutions. The violations cover obligations applying to the Company, Data Providers and Users, including requirements relating to data accuracy, consent, confidentiality, security, retention and the handling of KYC Reports.

Federal Decree-Law No. (30) of 2024 also provides for criminal liability for specified conduct, including unauthorised disclosure or access, breaches of confidentiality and the deliberate provision of false information. The framework therefore places enforceable responsibilities on each participant in the KYC process.

What the Framework Means in Practice

The practical significance of the framework is the move towards a shared and regulated infrastructure for customer information rather than KYC processes operating entirely in isolation. For customers, this may reduce repeated requests for the same identification and corporate information. For participating organisations, access to trusted data may help streamline parts of the onboarding and due diligence process.

Greater integration also places more emphasis on data quality. Data Providers are responsible for verifying the information they submit, the Company is responsible for the security and operation of the Platform, and Users remain responsible for the lawful handling of KYC Reports.

The Platform should not, however, be treated as a substitute for risk-based customer due diligence. Financial Institutions, DNFBPs and Virtual Asset Service Providers must continue to comply with the AML/CFT/PF requirements applicable to them. Organisations will therefore need to consider how use of the Platform fits within their existing onboarding, recordkeeping and compliance procedures.

Practical Takeaway

Cabinet Resolutions No. (55) and No. (56) of 2026 provide the operational and enforcement framework for the UAE’s KYC Digital Platform. The broader development is the creation of a more integrated system for collecting and using verified customer information, with defined responsibilities for those providing, managing and accessing that data.

Organisations participating in the Platform should ensure that their procedures address data accuracy, consent, confidentiality, retention and secure handling, while continuing to meet any separate AML/CFT/PF obligations that apply to them.

The Central Bank has indicated that future phases will expand the Platform’s capabilities and deepen its integration with relevant stakeholders, suggesting that its role in customer onboarding and compliance processes is likely to develop further.