Introduction
A buyer completes a KYC form, submits identification documents to the developer, and provides information about the purchase.
Later, the broker requests some of the same documents—or asks for additional evidence.
The buyer responds:
“I already submitted everything to the developer. Why should I provide it again?”
The customer’s frustration may be understandable. Repeated requests can appear disorganized, intrusive, or unnecessary.
At the same time, a brokerage cannot always treat another party’s KYC process as its own. It must understand its role in the transaction, assess the relevant risks, and retain sufficient evidence supporting its decision.
This creates a practical challenge:
How can agents and compliance teams obtain what is genuinely required without creating unnecessary friction or appearing to place the deal at risk?
Who Owns the Client?
Commercially, brokers and developers may talk about “owning the client.” From an AML perspective, that is not the most useful question.
The same person may be:
- a customer of the developer,
- a direct client of a brokerage,
- represented by another broker,
- a key party in the transaction handled by the seller’s broker,
- involved with several brokers or developers across different transactions.
Responsibility depends on the relationship and the role each firm performs. A KYC file submitted to one firm does not automatically transfer to every other firm involved.
This does not mean each firm should blindly collect the same documents. It means each firm must determine what information it requires, what it can lawfully obtain from another party, and what additional evidence is necessary for its own assessment.
A KYC Form Is Not the Complete CDD Decision
A completed KYC form records information provided by the customer. Customer Due Diligence goes further.
CDD may include:
- identifying and verifying the customer,
- identifying beneficial owners or representatives where relevant,
- screening the relevant parties,
- understanding the purpose and nature of the relationship,
- assessing customer and transaction risk,
- reviewing source of funds or source of wealth where required,
- documenting the decision to proceed, escalate, or decline.
Therefore, the statement “the developer has the KYC” does not necessarily tell the brokerage:
- which information was verified,
- which parties were screened,
- whether the documents remain current,
- what risk assessment was performed,
- whether the information can be shared,
- whether the evidence is sufficient for the brokerage’s role.
The existing file may be useful, but it must first be understood.
Compliance Officer or MLRO?
The terms Compliance Officer and Money Laundering Reporting Officer, or MLRO, are sometimes used differently.
The Compliance Officer generally oversees the broader AML framework, including CDD, risk assessment, screening, policies, training, controls, and records. The MLRO function focuses particularly on receiving and assessing internal concerns and deciding whether suspicious activity should be reported to the FIU.
In many UAE real estate firms, the same appointed person performs both functions. Current supervisory guidance therefore commonly refers to the combined CO/MLRO function.
Whatever title is used, the person must be able to exercise independent judgment without inappropriate sales pressure.
Why the Broker May Still Need to Make Its Own Request
From the broker’s perspective, this may be the first time it has requested the information.
From the client’s perspective, however, it feels like the same KYC process is being repeated. The client sees one property purchase, while the developer, buyer’s broker, seller’s broker, and other involved firms may each see a separate business relationship or compliance responsibility.
This difference in perspective creates much of the frustration.
The broker may need to make its own request where:
- it cannot access the information previously submitted to the developer or another broker,
- there is no documented arrangement allowing reliance on the other firm’s CDD,
- the documents previously collected are expired, incomplete, or unsuitable for verification,
- the broker needs information relevant to its particular role in the transaction,
- the transaction circumstances have changed since the earlier KYC was completed,
- the customer, payer, representative, or ownership structure requires further review,
- the risk assessment identifies a need for source of funds, source of wealth, or other supporting evidence,
- the other firm’s file does not show what screening, verification, or risk assessment was performed.
This does not mean the broker should automatically request the entire KYC package from the beginning.
Before making its own request, the broker should determine:
- What has the client already submitted elsewhere?
- Can any of that information be shared with the client’s authorization?
- Can the broker formally rely on any CDD performed by the other firm?
- Is the existing information current, complete, and relevant to the broker’s role?
- What specific information or evidence is still missing?
- Why is that information necessary?
The objective is to satisfy the broker’s own responsibility while avoiding duplication wherever reasonably possible.
The distinction is important:
The client may be receiving the same question for the second or third time, even though each firm is asking it for the first time.
How to Make the Request Without Damaging the Client Relationship
The way a request is communicated can determine whether the customer cooperates or becomes defensive.
1. Acknowledge the Customer’s Position
Begin by recognizing what the customer has already done.
“I understand that you already completed the developer’s KYC process and submitted your documents.”
This confirms that the firm has listened before making its own request.
2. Explain the Firm’s Responsibility
Avoid relying on phrases such as “Compliance wants it” or “It is company policy.”
A clearer explanation is:
“The developer and our brokerage have different roles in the transaction. Our firm must maintain sufficient evidence supporting its own AML review.”
Staff may explain routine CDD requirements, but they should never reveal that a suspicious transaction report is being considered or disclose confidential internal reporting decisions.
3. Request the Specific Gap
The customer should know exactly what is needed.
Instead of:
“Please send additional financial documents.”
Use:
“We need evidence showing the origin of the funds being used for this payment. The bank statement confirms the balance, but it does not show where the funds came from.”
A specific request appears reasoned rather than arbitrary.
4. Offer Appropriate Alternatives
Where the CO/MLRO considers it acceptable, the customer may be offered alternatives:
“You may provide the document directly, authorize the developer to share the relevant information, or provide another document that establishes the same source.”
The agent should not decide independently that an alternative is sufficient. That decision belongs to compliance.
5. Confirm What Happens Next
Tell the customer how the request will be handled:
“Once received, Compliance will review it within one business day. We will consolidate any remaining questions so that you are not contacted repeatedly.”
Clear timing and a single coordinated request can reduce more frustration than simply asking for fewer documents.
What Agents and CO/MLROs Should Do
Agents
Agents should:
- introduce possible AML requirements early,
- avoid promising that no further evidence will be required,
- use an approved explanation and document checklist,
- avoid criticizing compliance in front of the customer,
- refer technical objections to the CO/MLRO,
- report resistance, contradictions, or changing explanations.
The agent’s role is to keep communication professional—not to approve or waive AML requirements.
CO/MLROs
The CO/MLRO should:
- ensure every request has a clear purpose,
- review existing information before requesting material the client may have supplied elsewhere,
- consolidate requests wherever possible,
- accept reasonable alternative evidence where appropriate,
- take over sensitive or complex discussions,
- apply requirements consistently,
- document the request, response, and final decision.
Management should support this independence while ensuring that the compliance process is reasonably organized and timely.
Common Customer Responses
| Customer response | Better approach |
|---|---|
| “I submitted everything to the developer.” | Check whether the information can be shared or relied upon, then request only missing, outdated, or insufficient evidence. |
| “Another broker did not ask for this.” | Explain that each firm must assess its own role and the risk presented by the transaction. |
| “This information is private.” | Explain why it is required, who will review it, and how it should be submitted securely. |
| “Approve the deal now and I will provide it later.” | Clarify which checks must be completed before the firm can proceed. |
| “If you insist, I will use another broker.” | Remain professional and escalate the matter. A necessary control should not be removed solely because of commercial pressure. |
When Does Resistance Become an AML Concern?
Resistance is not automatically suspicious. The customer may be concerned about privacy, repetition, delays, or poor communication.
Closer review may be appropriate where the customer:
- refuses to provide information necessary to understand the transaction,
- repeatedly changes their explanation,
- provides contradictory documents,
- pressures staff to bypass required checks,
- attempts to use status, urgency, or transaction value to avoid review,
- refuses reasonable alternatives without explanation.
The distinction is between a customer questioning an inconvenient process and a customer preventing the firm from understanding material risk.
Can the Firm Rely on Another Party’s KYC?
UAE AML rules permit reliance on CDD performed by a third party only under defined conditions.
The relying firm should be able to obtain the necessary identification information immediately, receive supporting documents without delay, and satisfy itself that the third party is appropriately regulated and applies suitable CDD and record-keeping measures.
An informal statement such as “the developer already completed KYC” is not, by itself, a documented reliance arrangement.
Even where reliance is permitted, the firm remains responsible for ensuring that its AML obligations are properly addressed.
Where InfoAML Helps
InfoAML helps real estate firms reduce unnecessary repetition by keeping customer information, documents, screening results, risk assessments, and compliance decisions structured in one place.
It also allows teams to record:
- which information was received,
- which documents remain outstanding,
- why further evidence was requested,
- how the customer responded,
- who reviewed and approved the decision,
- what evidence should be available during an inspection.
A structured process improves both customer communication and inspection readiness.
Conclusion
The customer is not necessarily wrong to question why another firm is requesting information they have already provided elsewhere.
The firm is also not wrong to require evidence supporting its own AML decision.
The best approach lies between unnecessary duplication and unsupported reliance. Firms should review what already exists, identify the genuine gaps, make proportionate requests, explain them professionally, and keep a clear record of the outcome.
The strongest position is not:
“Compliance asked for more documents.”
It is:
“We explained what our firm required, avoided unnecessary duplication, obtained sufficient evidence, and documented the decision.”
You May Also Find These Blogs Useful
- The Buyer Is Not Our Client: Do We Still Have AML Duties?
- The Buyer Comes Through Another Broker: Who Handles AML?
- The Buyer Is Not the Payer: AML Risks in Third-Party Real Estate Payments
- The Buyer Signs Through a Power of Attorney: Who Do You Screen?
- A Trade License Is Not Enough: How to Identify the UBOs Behind a Company Buyer
- KYB vs KYC: What’s the Difference in UAE AML?