Regulatory & Compliance
How Sentrix aligns to recognised security and privacy frameworks, our approach to UAE data protection and financial-crime regulation, and how the platform maps to the regulatory obligations of the banks, acquirers, PSPs and EMIs that use it. We describe what the platform enables and are explicit about what is on the roadmap.
Last updated: 22 July 2026 · Governing law: United Arab Emirates
Regulatory context
Sentrix is a technology vendor, not a licensed financial institution. Our customers are the regulated entities — banks, acquirers, payment service providers and electronic money institutions, supervised in the UAE by the Central Bank of the UAE (CBUAE) or, for free-zone firms, the DFSA (DIFC) or FSRA (ADGM). Sentrix provides the decisioning, screening, case and evidence tooling those institutions use to meet their obligations; the regulatory accountability for onboarding, monitoring and reporting decisions remains with the institution.
Frameworks we align to
Sentrix's control framework is aligned to SOC 2 and ISO/IEC 27001 practices. Formal third-party attestation and certification are described honestly as in progress and on our roadmap — the controls themselves are implemented and can be reviewed with our security team. We do not claim completed certifications we do not yet hold, and we display no attestation badges we have not earned.
Data protection — UAE PDPL
Our baseline is UAE Federal Decree-Law No. 45 of 2021 (PDPL). We operate a controller/processor model: Sentrix is a processor for customer end-user data and a controller for account data. Depending on the free zone in which our contracting entity is finalised, the DIFC Data Protection Law 2020 or ADGM Data Protection Regulations 2021 may also apply. Our Privacy Policy sets out lawful bases, cross-border transfer mechanisms and data-subject rights, and our DPA provides the contractual data-protection terms including a technical and organisational measures annex. Customers subject to the EU/UK GDPR or the CCPA/CPRA are supported through those same mechanisms. We do not sell personal data.
Financial-crime — UAE AML/CTF & FATF
As a technology vendor we maintain a risk-based financial-crime programme aligned to UAE Federal Decree-Law No. 20 of 2018 (and Cabinet Decision No. 10 of 2019) and the FATF Recommendations, covering customer due diligence, sanctions and PEP screening, ongoing monitoring, escalation, record-keeping and reporting to the UAE FIU via goAML where an obligation applies to us. The platform, in turn, provides the identity verification, sanctions/PEP/adverse-media screening, decisioning, ongoing monitoring, case management and audit trails that customers use to meet their own obligations. Full detail is in our AML & CTF Policy.
Data residency
Customer-selectable data-residency options — including UAE-region hosting to meet local requirements — are on our roadmap and are not yet generally available. Today the platform runs in a single primary region. Where data crosses borders, the PDPL transfer grounds and supplementary measures apply. Contact us to discuss the residency requirements for your jurisdiction and our delivery timeline.
Mapping to customer regulatory obligations
| Obligation area | How Sentrix helps |
|---|---|
| KYC / identity | Identity verification inputs and orchestration |
| AML / sanctions | Sanctions, PEP and adverse-media screening with configurable thresholds |
| KYB | Business and counterparty risk signals within decisioning |
| Ongoing monitoring | Re-screening and event-driven review as risk or lists change |
| Suspicious-activity workflow | Alerting, case management and disposition to support the customer's FIU/goAML reporting (the customer files) |
| Recordkeeping & audit | Append-only decision/override logs to support examiner evidence (WORM/hash-chaining on the roadmap) |
| Governance | RBAC and role separation (four-eyes approval on the roadmap) |
Responsible decisioning & transparency
Sentrix favours explainable, rules-and-scores decisioning so customers can understand, document and defend outcomes. Configurable thresholds let each institution encode its own risk appetite, and audit trails record why a decision was reached and who overrode it. Customers remain accountable for their decisions; sandbox outputs are simulated and must not be used for real decisions.
Need our security package or a compliance questionnaire completed? Email compliance@sentrix.world or see the Trust Center for policies and status.