Internal audit & compliance · Dubai, UAE

Assurance your board can sign off on.

BSRS & Associates is the internal audit and compliance partner for UAE companies. We audit your controls, write the policies and procedures that fix the gaps, put the protocols in place, and stay on as your advisor so you remain compliant as rules change.

IIA Global Standards aligned Reports in English & Arabic Mainland, free zone, DIFC & ADGM
WP-P2P-04 · Procurement cycle ● High

Vendor master changes approved by the same user who raised them

Condition
38 of 212 bank-detail changes had no independent approval.
Criteria
Delegation of Authority §4.2, segregation of duties.
Risk
Payment diversion and fictitious vendors.
Action
System-enforced maker-checker by 30 Nov; finance to re-verify 38 accounts.
Owner: Finance Controller Reviewed · Partner
Frameworks we audit against
IIA Global Internal Audit StandardsCOSO 2013COSO ERMISO 37301ISO 27001FATF
WP-01
Services

One firm for the three lines of defence.

Run your full internal audit function, support an in-house team on specialist areas, or take a single targeted review. Every engagement is scoped to your risk register, not a standard checklist.

IA

Internal audit, outsourced or co-sourced

A complete function reporting to your audit committee, or specialists alongside your team.

  • Risk-based annual plan
  • Audit committee reporting
  • Head of IA on retainer
RC

Regulatory compliance reviews

Independent testing against the rules your regulator will inspect you on.

  • CBUAE, DFSA, FSRA, VARA, SCA
  • Compliance monitoring plans
  • Inspection readiness
AML

AML/CFT & sanctions

Programme reviews for financial institutions and designated non-financial businesses.

  • Enterprise-wide risk assessment
  • goAML and STR process testing
  • Independent AML audit
TAX

Corporate Tax & VAT controls

Control reviews that keep filings defensible before the FTA asks questions.

  • Tax control framework
  • VAT return health checks
  • Transfer pricing documentation review
ICF

Internal controls & SOPs

Design, document and test the controls behind your financial statements.

  • Process mapping and RACM
  • Delegation of authority
  • Policy and SOP drafting
ERM

Enterprise risk management

A risk framework your management actually uses to make decisions.

  • Risk appetite and register
  • Key risk indicators
  • Board risk workshops
ITA

IT, cyber & data privacy audit

General IT controls, ERP access and data protection reviews.

  • ITGC and ERP access reviews
  • PDPL readiness
  • Third-party and cloud risk
FOR

Fraud & investigations

Fact-finding when something has gone wrong, and controls so it doesn't again.

  • Fraud risk assessment
  • Data analytics on payments
  • Whistleblowing case support
WP-01A
Partnership

Your compliance partner, from policy to practice.

An audit tells you where the gaps are. BSRS also stays to close them: we write the policies, build the procedures, train your people and run the compliance calendar with you, year after year.

  1. Assess

    Gap assessment

    Map every obligation from your licence, regulator and UAE law against what you do today.

    Obligations register
  2. Design

    Policies & procedures

    Board-approved policies and step-by-step procedures written for your business and systems.

    Policy manual & SOPs
  3. Implement

    Protocols in place

    Configure controls, screening, approval workflows and records so the policies work in daily operations.

    Live controls & templates
  4. Train

    People who know the rules

    Role-based training for the board, management and staff, with attendance records for your regulator.

    Training log
  5. Monitor

    Ongoing compliance

    Monthly monitoring, regulatory change alerts, filing calendar and board compliance reports.

    Quarterly board report

Policy & procedure library

Drafted to UAE requirements and tailored to your operations. Each comes with procedures, forms and an implementation checklist.

  • AML/CFT & sanctions policy KYC · CDD/EDD · goAML
  • Compliance manual & monitoring plan
  • Delegation of Authority matrix
  • Procurement & vendor onboarding
  • Anti-bribery & conflicts of interest
  • Whistleblowing & investigations
  • Code of conduct
  • Data protection & privacy PDPL
  • Information security & access control
  • Corporate Tax & VAT procedures
  • Business continuity & incident response
  • Related-party transactions
Project

Compliance set-up

For new licences, new markets or a first regulatory inspection.

  • Gap assessment
  • Policies & SOPs drafted
  • Implementation support
  • Staff training
Regulated firms

Outsourced compliance function

For firms that need a compliance officer or MLRO support.

  • Outsourced compliance officer where your regulator permits
  • MLRO and deputy MLRO support
  • Regulator correspondence & inspections
  • Annual independent review by a separate BSRS team
WP-02
Approach

How an engagement runs.

A typical process audit takes four to six weeks from kick-off to final report. You know the scope, team and fee before we start.

1

Discovery & scope

A free discovery session under mutual NDA. We look at your business, regulators and risk register, then agree objectives and a fixed fee. Nothing is billed before you sign off the scope.

Engagement letterWeek 0
2

Risk assessment

Walkthroughs with process owners to map risks and key controls.

Risk & control matrixWeek 1
3

Fieldwork

Control testing, sampling and data analytics on full populations where possible.

Working papersWeeks 2–4
4

Report

Rated findings with agreed management actions, owners and dates. Closing meeting with leadership.

Board-ready reportWeek 5
5

Follow-up

We re-test each action on its due date and report closure status to the audit committee.

Action trackerQuarterly
WP-03
Reporting

What your audit committee receives.

Every finding follows the same structure, so directors can read twenty of them in ten minutes and know exactly what to ask.

Condition

What we found, with the numbers: how many, how much, how often.

Criteria

The policy, law or standard it was tested against.

Cause

Why it happened, whether people, process or system.

Effect

The financial, regulatory or reputational exposure in AED terms where possible.

Action

An agreed fix with a named owner and a due date we will re-test.

Findings by audit area Example · FY2026 plan

Procure-to-pay
7
Revenue & credit
5
AML/CFT
4
IT general controls
5
Payroll & HR
2
HighMediumLow
23Actions agreed
17Closed & re-tested
2Overdue

Illustrative figures showing the report format.

WP-04
Regulations

Built around UAE rules.

The laws and regulators our compliance reviews most often test against.

AreaKey requirementHow we help
AML/CFTFederal Decree-Law No. 20 of 2018 and its implementing regulations · goAMLRisk assessment, KYC file testing, independent AML audit
Corporate TaxFederal Decree-Law No. 47 of 2022 · return due 9 months after year endTax control framework, filing readiness, TP documentation
VATFederal Decree-Law No. 8 of 2017 · returns due 28 days after periodReturn reviews, input tax recovery testing
Data protectionFederal Decree-Law No. 45 of 2021 (PDPL), DIFC and ADGM data lawsData mapping, privacy controls, gap assessment
Beneficial ownershipCabinet Decision No. 58 of 2020 · updates within 15 daysUBO register review and governance checks
Financial regulatorsCBUAE, DFSA (DIFC), FSRA (ADGM), VARA, SCA rulebooksCompliance monitoring, internal audit for regulated firms
WP-05
Sectors

Where we work.

Banks & finance companies CBUAE DIFC & ADGM firms DFSA · FSRA Virtual asset providers VARA Real estate & construction Precious metals & jewellery DNFBP Healthcare Trading & distribution Logistics & free zones Family businesses Government-related entities
WP-06
Why BSRS

The attention of a boutique, the rigour of a network.

Partners do the work

The partner who scopes your engagement attends walkthroughs, reviews every working paper and presents to your board. No hand-off to a rotating junior team.

Advice and assurance, kept separate

When we help design your policies and controls, a different BSRS team performs the independent review, so you get a partner and an objective audit without a conflict.

Fixed fees, agreed upfront

Discovery is free and covered by an NDA. You then receive a scoping proposal within two business days with a fixed fee per audit, and no open-ended hourly billing.

WP-06A
Models

In-house team or BSRS?

What a mid-sized UAE group typically gets from each option.

Building in-houseBSRS outsourcedBSRS co-sourced
Time to first audit4–6 months to recruit4–6 weeks2–4 weeks
Specialists (IT, AML, tax)Hired separately or missingIncluded as neededOn call for your team
Independence from managementReports up through the organisationExternal and objectiveExternal review of key areas
Cost profileFixed salaries, visas, trainingFixed annual retainerPay per engagement
Best suited toLarge groups with steady audit volumeGroups with no IA function todayGroups with a small IA team
WP-07
Health check

How ready is your control environment?

Six questions. Your answers stay on this page.

WP-08
FAQ

Common questions.

Is internal audit mandatory in the UAE?

Not for every company. It is expected or required for many regulated entities, such as banks and finance companies, listed companies and firms supervised by the DFSA or FSRA. Many private groups adopt it anyway because lenders, investors and boards ask for independent assurance.

What is the difference between internal and external audit?

External audit gives an opinion on your financial statements for shareholders. Internal audit reports to management and the board on whether risks are controlled across operations, compliance and finance, and recommends improvements.

Should we outsource or build an in-house team?

Outsourcing gives you a full team of specialists without permanent headcount, and independence from the functions being audited. Co-sourcing suits companies with a small in-house team that needs IT, AML or tax specialists for specific reviews.

Can you both set up our compliance and audit it?

Yes, with safeguards. Under the IIA Standards, people who designed a control should not audit it. We assign separate teams to advisory and assurance work, and the audit report states this so your board and regulator can rely on it.

We just received a new licence. Where do we start?

Most new licensees start with our compliance set-up project: a gap assessment against the licence conditions, a policy manual and procedures, implementation of screening and record-keeping, and staff training. Many then move to a monthly retainer for ongoing support.

How are fees calculated?

We quote a fixed fee per audit area based on the size of the process, number of locations and the testing required. An annual plan is priced as a retainer with quarterly reporting included.

Do you work outside Dubai?

Yes. We serve clients across all seven emirates, including mainland, free zone, DIFC and ADGM entities, and support group audits in other GCC countries.

WP-08A
Insights

Insights for audit committees.

Short, practical notes on UAE regulation and control practice.

Corporate Tax · 6 min read

Five controls the FTA will expect behind your first Corporate Tax return

Where tax data breaks between the ERP and the return, and how to evidence the fix.

Coming soon
AML/CFT · 5 min read

What an independent AML review should test, and what most miss

Moving beyond policy review to sample-testing KYC files, screening hits and goAML reporting.

Coming soon
Governance · 4 min read

Setting up internal audit for a UAE family business

A first-year plan for groups that have never had an audit committee.

Coming soon
WP-09 · Contact

Tell us what keeps your audit committee up at night.

A partner will reply within one business day to arrange a scoping call.

Emailhello@bsrs.ae
Phone+971 4 000 0000
OfficeUnit 901, Sobha Ivory Tower 2
Business Bay, Dubai, UAE