Compliance Audit Guide in DIFC: Documentation Requirements
The DIFC applies its own employment and data protection law, not the federal versions.
Reviews in the DIFC rarely turn on a prohibited act. They turn on a company being unable to produce the document showing it did the permitted thing. This guide identifies who is entitled to ask — the Registrar of Companies, the DFSA, the Commissioner of Data Protection, and federal tax administration, which reaches DIFC entities like any other — and sets out the core file each expects: registers and beneficial ownership records reconciled to the filings actually made, resolutions behind every transfer and related-party transaction, employment records kept to DIFC standards, anti-money-laundering files and data protection documentation. It closes with the points where files usually break, including group policies imported from a parent company that describe another jurisdiction.
A compliance audit in the DIFC rarely fails because a company did something forbidden. It fails because the company cannot produce the document that proves it did the permitted thing. The register was never updated after a share transfer, the beneficial owner information still names a shareholder who exited two years ago, the board approved a transaction by email and nobody wrote a minute. The rule was followed; the record was not kept.
This guide sets out what a DIFC entity should be able to hand over on request, who is entitled to ask, and the points where files most often turn out to be incomplete.
Who can ask, and for what
DIFC entities answer to more than one body, and each looks at a different part of the file.
The DIFC Registrar of Companies is concerned with corporate standing: that the entity exists in the form its licence says, that its registers are accurate and current, that filings have been made, and that it operates from the registered address it has given.
The Dubai Financial Services Authority supervises firms that hold a financial services licence. Its interest is in the conditions attached to that licence: permitted activities, capital and reporting, the individuals approved to hold controlled functions, client money and client classification, and anti-money-laundering systems.
The Commissioner of Data Protection supervises the DIFC's own data protection regime, which is separate from Federal Decree-Law No. 45 of 2021 and applies to personal data processed in the Centre.
Alongside these sits federal tax administration, which reaches DIFC entities like any other. Being established in the Centre does not place a company outside Federal Decree-Law No. 47 of 2022 on corporate tax, which applies to financial years starting on or after 1 June 2023, with 0% on taxable income up to AED 375,000 and 9% above. Whether any free zone treatment is available on particular income is a question to settle with advice before a return is filed, not after.
The DIFC also applies its own employment law rather than the federal employment decree-law, and its own courts hear disputes. Employment records are therefore audited against DIFC requirements, not federal ones.
The core document set
Whatever prompts the review, the same core file is usually requested first:
- the certificate of incorporation or registration, the current commercial licence, and the articles of association in their latest adopted form;
- the register of members or shareholders, the register of directors and officers, and the record of ultimate beneficial owners, each reconciled to the filings actually made;
- every share transfer, allotment or capital change, with the board and shareholder resolutions that authorised it;
- minutes of board and shareholder meetings, including written resolutions passed outside a meeting;
- the lease or licence for the registered premises, and evidence that the registered address is where the entity can actually be reached;
- financial statements, prepared and audited where the entity is required to have them audited, with the underlying accounting records;
- employment contracts, payroll records, leave and end-of-service calculations for DIFC-based staff;
- where the entity is a designated non-financial business or a licensed firm, its anti-money-laundering policy, risk assessment, customer due diligence files and suspicious activity reporting records;
- data protection records: the notification made to the Commissioner, the processing register, privacy notices, processor agreements and the assessment supporting any transfer of personal data out of the Centre.
Where the file usually breaks
Registers that were never brought up to date
Corporate registers are living documents. A transfer of shares, a change of director, a new controller, a change of registered address or a change in beneficial ownership all require the internal register to be amended and the corresponding filing to be made. The common failure is doing one and not the other, so that the company's own register and the Registrar's record disagree. An auditor who finds that difference will widen the review rather than close it.
Decisions taken without a record
Approvals given informally, by message or in conversation, leave nothing behind. Related-party transactions, intra-group loans, guarantees, service agreements and the appointment of officers should each be traceable to a dated resolution that identifies who approved it and what was disclosed. This matters most where a director had an interest in the matter approved.
Group documents that describe another jurisdiction
Policies imported from a parent company frequently reference statutes, regulators and procedures that do not apply in the DIFC. A data protection policy written for a European group, or an employment handbook written for the mainland, is evidence that the local requirement was not considered. Localise the policy or state clearly which part of it governs DIFC operations.
Substance and history
Economic substance obligations were cancelled for financial years ending after 31 December 2022 by Cabinet Decision No. 98 of 2024, but they remain live for the financial years from 2019 to 2022. Notifications, reports and the evidence behind them for those years should stay in the file, and should not be discarded on the basis that the regime no longer applies going forward.
Contracts and the disputes that follow a bad file
Audit findings and commercial disputes draw on the same documents. A counterparty arguing that an agreement was never properly authorised will point to the absence of a resolution. A claim that a limitation of liability does not bind will turn on which version of the terms was signed and whether the signatory had authority. Keeping executed originals, signature authority schedules and the approvals behind them in one place is as much protection in commercial dispute resolution as it is in a regulatory review.
The same is true of allocations of risk. Indemnities, caps and exclusions only work if the executed document can be produced and the person who signed it held the authority to do so. Gross negligence and wilful misconduct cannot be excluded, so provisions that try to are worth revisiting before they are tested.
A practical annual routine
Once a year, and before any transaction that will put the file in front of a third party, work through the following. Reconcile each register against the Registrar's record. Confirm the licence covers what the business is actually doing, and nothing it is not. Check that every officer and controlled-function holder still holds the approval their role requires. Confirm the registered address and lease are current. Match the accounting records to the financial statements. Review the data processing record against what the business now does with personal data, particularly where processing has moved to a new system or supplier. Confirm the tax registration and the filing position for the current period.
Where the review shows a gap, correct it and record the correction with its date. A file that shows a problem found and fixed reads very differently from one in which the problem is simply absent.
For help reviewing a DIFC entity's corporate and regulatory records, or preparing for a scheduled inspection, our corporate legal services team can work through the file with you.
Disclaimer: The information provided in this article is for general informational purposes only and does not constitute legal advice. Readers should seek professional legal advice tailored to their specific circumstances before making any decisions or taking any action based on the content of this article.
Nour Attorneys Team
Related Resources
Explore more of our insights on related topics:
- Company Formation Checklist for UAE Investors
- Compliance Audit Guide for Financial Entities
- Contract Drafting Protocol Guidelines
- Employee Onboarding Legal Requirements