In the UAE, a small number of government systems handle identity verification for licensed financial institutions. Understanding how they connect matters. It's exactly what CBUAE expects a compliant onboarding process to get right.
The Emirates ID is the mandatory ID card for UAE citizens and residents. It's issued by the Federal Authority for Identity, Citizenship, Customs & Port Security, known as ICP. The card combines:
The ICP Validation Gateway is the online service that lets an authorised organisation check that a given Emirates ID is genuine, and confirm its current status, directly against ICP's own records.
CBUAE guidance is clear on this point. When a licensed financial institution verifies an Emirates ID, whether in person or electronically, it must use one of these:
It must also keep a copy of both the Emirates ID and the digital verification record.
UAE Pass launched in 2018. It's a joint initiative of the Telecommunications and Digital Government Regulatory Authority, the Abu Dhabi Digital Authority, and Smart Dubai. It gives residents a single mobile identity for government services and digital signatures.
Here's the part worth knowing: UAE Pass isn't an independent identity source. It relies on the ICP Validation Gateway underneath it. So whether you integrate through UAE Pass or go directly to the ICP gateway, you're ultimately checking against the same authoritative record. The difference is the integration path, not the source of truth.
CBUAE doesn't just mandate a specific system and stop there. It expects licensed institutions to actually understand the assurance level of any digital ID system they use. Where UAE law hasn't already named a required system, CBUAE points to frameworks like the NIST Digital Identity Guidelines as a reference for assessing reliability, covering both identity proofing at enrolment and authentication at the point of use.
In practice, for Emirates ID checks specifically, the expectation is straightforward: use the ICP Validation Gateway, UAE Pass, or another government-supported solution, and keep the verification record. For any other digital ID system you might consider, it's on you to assess and document its reliability yourself.
Here's a mistake that shows up often: checking an Emirates ID visually, or against static data, without actually querying the ICP Validation Gateway or UAE Pass. This tends to happen in manual or partly digitised onboarding flows.
CBUAE's AML/CFT framework treats the gateway check, not a visual look at the card, as the actual verification step. Skipping it means you haven't met the documented expectation, even if you kept a copy of the card
Once an Emirates ID has been verified through the ICP Validation Gateway or UAE Pass, MemberCheck picks up the next stage: PEP, sanctions, and adverse media screening for the verified individual, plus the case management and audit trail you need to evidence it. MemberCheck doesn't perform Emirates ID validation itself. It's the screening layer that comes right after.

No. UAE Pass relies on the ICP Validation Gateway underneath it. Both check against the same ICP record, just through different integration paths.
No. CBUAE guidance requires a check through the ICP Validation Gateway, UAE Pass, or another government-supported solution, plus keeping the verification record. A visual check alone isn't enough.
For Emirates ID checks specifically, yes, one of the three named options. For any other digital ID system, the institution is responsible for assessing its reliability itself.