Industries

AI for UAE Banks & Fintechs

Stop fraud, automate eKYC, and handle call volume at scale — with models you can run inside your own regulated environment.

  • Facial recognition with liveness detection and automated document verification
  • Real-time fraud scoring at thousands of checks per hour, sub-second
  • Custom voice AI tuned to financial terminology and Gulf accents
  • Deployable in your own VPC or on-premise — CBUAE and PDPL aligned
  • Bilingual Arabic/English across chat, voice, and document flows

How We Help

Identity Verification & eKYC

  • Facial recognition with liveness detection
  • Automated document and Emirates ID verification
  • Real-time fraud scoring with regulatory reporting
  • Thousands of verifications per hour, sub-second response
Automate eKYC and onboarding

Fraud & Risk Scoring

  • Real-time scoring engine on transactions and applications
  • Pattern detection tuned to your fraud history
  • Confidence thresholds with human review escalation
  • Audit-ready reporting for AML/CFT obligations
Cut fraud losses

Voice AI for Contact Centres

  • Custom ASR trained on financial vocabulary and regional accents
  • Real-time transcription with speaker diarization
  • Handles high concurrent call volume with low latency
  • Integrates with your existing call-centre infrastructure
Scale your contact centre

Results

50x

reduction in identity fraud (my UAE fintech deployment)

Sub-second

fraud scoring response time per verification

1000s/hr

identity verifications processed at peak

The Monday after go-live

It's 9am Monday and onboarding is running itself. A new customer photographs their Emirates ID and face on their phone; liveness passes, the documents verify, and the fraud engine scores the application — all in under a second, before they've put the phone down. On the risk desk, the weekend's flagged cases are already sorted by score: the clear ones auto-approved, the doubtful ones queued with the exact reason attached. The fraud that used to slip through at fifty times this rate simply isn't getting in.

How identity & fraud AI fits a regulated bank

Onboarding runs as five steps, and it helps to see where each one lives. First, capture: the customer's document and face. Second, liveness and anti-spoofing, tested against ISO/IEC 30107-3. Third, the authoritative identity check through UAE PASS and ICP. Fourth, the fraud score. Fifth, the routing decision: straight to auto-approve, or out to manual review.

Here is the part that matters to a regulator. The AI augments official verification; it does not replace it. It does not replace sanctions screening, and it does not replace your goAML filing. It sits in front of those controls and makes them faster.

Data placement follows the same logic at every step. The biometric template, the extracted features, and the fraud score all stay inside your perimeter. None of it is shipped to an external service to be scored. And the human-in-the-loop boundary is explicit: when a case is held, the MLRO sees a reason code, not a verdict from a model nobody can interrogate.

Deployment & data residency for UAE banks

You have three ways to run this, and the difference between them is mostly about how much outsourcing burden you want to carry.

One: bank-owned hardware, including a fully air-gapped build. Two: a single-tenant UAE VPC. Three: a hybrid of the two. Whichever you pick, the weights and the data stay in-country.

For banking specifically, on-premise earns its keep. A third-party or hyperscaler AI API is outsourcing under the CBUAE Outsourcing Regulation and its Standards for Banks. That pulls in due diligence, audit rights, sub-processor terms, the whole file. Run the model in your own environment and that vendor is no longer a sub-processor in your chain. The dependency is gone.

On residency, the rule is narrower than the marketing usually admits, so I'll state it straight. The UAE PDPL (Federal Decree-Law 45/2021) does not cover banking and credit data. That data is carved out, and onshore banks follow CBUAE rules instead. The free zones differ by licence: DIFC runs under DPL 5/2020 and Regulation 10, ADGM under the DPR 2021. They are not the same regime, and I won't lump them together. The payoff for keeping everything onshore and in your own environment is concrete: faster sign-off, a simpler audit, and no cross-border transfer paperwork to maintain.

Accuracy, false positives, and model governance

If you sit on the risk or audit side, this is the section you actually care about, so it leads with the tradeoff rather than the demo. Catch more fraud and you reject more good customers; relax the threshold and more fraud gets through. That is the dial. I set it against your risk appetite, with a target false-reject rate in the low single digits and 2–3% as the rough materiality line.

The numbers behind the claims are testable, not decorative. Liveness is measured to ISO/IEC 30107-3 through iBeta at Levels 1 and 2, with BPCER ≤15%. Face matching is benchmarked against ISO/IEC 19795 and NIST FRVT. For the people who examine this, the model carries versioning, drift monitoring, score explainability with reason codes, and an audit trail. None of that is optional.

One framing point worth getting right: the CBUAE treats a fraud-scoring model as a model. The Model Management Standards and Guidance of 21 December 2022 govern it as model risk. It is not some separate "AI law," and pretending otherwise just confuses the conversation.

The threat is real and worth naming, with the caveats attached. Industry estimates put the rise in deepfake onboarding attacks at over 300% in 2025, with an average regional loss in the region of USD 379k. Those are cited industry figures, not numbers from my own book, but they are why liveness testing is the first thing I harden, not the last.

Regulatory map: what CBUAE actually requires of AI in banking

A row of regulator chips tells you nothing about what each one demands, so here is the instrument-by-instrument version.

The Outsourcing Regulation and its Standards for Banks decide whether a third-party AI service counts as outsourcing. It does. The Consumer Protection Regulation (2020) and its Standards (2021) govern automated declines and complaint handling, which is the direct constraint on an eKYC system that says no to a real applicant. AML and CFT run on Decree-Law 20/2018, with Cabinet Decision 10/2019 and Decree-Law 26/2021, and that is where goAML, the FIU, and the MLRO-as-gatekeeper live. The Model Management Standards and Guidance cover model governance. PCI DSS v4.0.1 applies, but only scoped to the cardholder data environment, not the whole bank.

Then there is the free-zone split: a bank licensed in DIFC or ADGM is under that zone's data regime, not the onshore CBUAE one, and the onboarding architecture has to reflect which it is.

Underneath all of it sits the hosting-security backdrop: CBUAE technology-risk and ISO 27001 obligations, against the roughly 188 controls of the UAE Information Assurance Standards. I cite exact titles here and nothing else. No invented article numbers, because in this room a wrong citation is worse than no citation.

What a first engagement looks like

The pilot runs against your data, in your environment. No sample dataset, no shared cloud sandbox.

What I need from you is a labelled history of past cases, kept inside your perimeter, so there's a real baseline to measure against. The integration surface is the usual set: UAE PASS and ICP, your NFC and document capture, your core onboarding flow, and write-back into case management and the MLRO's goAML path.

The pilot measures what it claims. Presentation-attack detection against ISO/IEC 30107-3. Face matching against ISO/IEC 19795 and NIST FRVT. The change in false-reject and abandonment rates. Fraud loss against your own baseline. At the end you get one thing: a go or no-go, with the numbers attached.

If that's the kind of engagement you want, the next step is the same as everywhere else on this site. Message me on WhatsApp, or book a call. No new form to fill in.

Integrations

Core Banking SystemsUAE PASSEmirates ID eKYCAani Instant PaymentsAML / Fraud Engines

Regulatory Awareness

CBUAE RegulationsUAE AML / CFTDIFC / ADGMPCI DSSUAE PDPL
Case Study

AI-Powered Identity Verification

Identity fraud was causing significant losses and manual verification couldn't scale to handle growing user base.

Deliverables

  • Facial recognition system with liveness detection
  • Automated document verification pipeline
  • Real-time fraud scoring engine
  • Regulatory compliance reporting

Results

  • 50x reduction in identity fraud
  • Thousands of verifications per hour
  • Sub-second response time
View all case studies

Frequently asked questions

Can a bank run this on its own hardware?

Yes. Bank-owned hardware is the default I'd recommend, with a fully air-gapped option where you need it. The models, the weights, and the data all stay on your infrastructure. Nothing is gated on an external service or on me.

Is biometric, liveness-based eKYC permitted, and does it replace Emirates ID?

It's permitted, and no, it does not replace Emirates ID. UAE PASS and ICP remain the authoritative identity source. Liveness and face matching sit on top of that to confirm the person presenting the ID is the right person, live and present.

Does the data leave the UAE?

No. The biometric template, the features, and the fraud score are all computed inside your perimeter. Run on-premise or in a single-tenant UAE VPC and nothing is shipped abroad to be processed.

How do you control false positives?

With thresholds tuned to your risk appetite, not factory defaults. The target is a false-reject rate in the low single digits, with 2–3% as the materiality line, and every decline carries a reason code so you can audit where the line is sitting.

How is a fraud score explained to a declined applicant?

Every decision comes with a reason code, not a bare "rejected." That gives your complaint-handling team something concrete to work from, which is what the Consumer Protection Standards expect of an automated decline.

How long is a pilot, and what data do you need?

The pilot runs against your own data, in your own environment. What I need is a labelled history of past cases inside your perimeter to build a baseline. The output is a go/no-go decision with the accuracy and false-reject numbers measured, not estimated.

Ready to talk?

No RFPs, no gatekeepers — message us on WhatsApp or book a discovery call.