1. Compliance Framework (DIFC)
Haqeeba Tech Limited maintains a unified compliance programme mapped to DIFC regulatory requirements. Our programme is built on ISO 27001, extended with SOC 2 criteria, and aligned with sector-specific requirements for financial services, government, and healthcare within the DIFC and UAE.
Governance: Quarterly compliance reviews by leadership. Annual internal audit. Continuous monitoring via automated controls. Regulatory reporting to DIFC Authority and Commissioner of Data Protection as required.
2. Certifications & Attestations
| Standard | Scope | Auditor | Validity |
|---|---|---|---|
| SOC 2 Type II | Security, Availability, Confidentiality | A-LIGN | Annual (renewed Q1 2026) |
| ISO 27001:2022 | ISMS (all cloud/on-prem) | BSI | 3-year (surveillance annual) |
| ISO 27701 | PIMS extension | BSI | Aligned with ISO 27001 |
Penetration testing: Annual (Bishop Fox). Continuous: SAST/DAST/SCA daily, dependency scanning weekly.
3. DIFC Regulatory Compliance
| Regulation | Applicability | How We Comply |
|---|---|---|
| DIFC Data Protection Law No. 5 of 2020 | All Personal Data processing | DPA, SCCs, DPIA, DPO, Art. 28 addendum, breach notification (72hr) |
| DIFC Data Protection Regulations | Regulatory details | Implemented in policies, procedures, contracts |
| DIFC Law No. 1 of 2020 (Companies Law) | Corporate governance | Registered entity, annual filings, registered office |
| DIFC Law No. 4 of 2019 (IP Law) | Intellectual property | IP ownership, licensing, enforcement |
| DIFC Employment Law | Staff | Contracts, policies, DIFC Employment Law compliance |
4. Data Protection (DP Law 2020)
4.1 Data Processing Addendum (DPA)
Standard DPA incorporated into our Terms. Includes: DIFC-approved SCCs, sub-processor management, audit rights, breach notification (72 hours to Commissioner), data return/deletion on termination.
4.2 International Transfers (DP Law 2020 Part 4)
Primary infrastructure: DIFC/UAE. Sub-processors outside DIFC covered by DIFC-approved SCCs + supplementary measures (encryption, access controls, pseudonymisation). Data residency options available on Enterprise — see our security program.
4.3 Data Subject Rights (DP Law 2020 Part 3)
Automated portal for access (Art. 13), rectification (Art. 14), erasure (Art. 15), portability (Art. 17), restriction (Art. 16), objection (Art. 18), withdraw consent (Art. 9). Response ≤30 days. See our Privacy Policy for details.
4.4 Breach Notification (DP Law 2020 Art. 30)
Internal detection → 24hr assessment → customer notification without undue delay (max 72hr). Regulatory notification to DIFC Commissioner within 72 hours.
5. Financial Services Regulations (DIFC/DFSA)
| Regulation | Relevance | Controls |
|---|---|---|
| DFSA Rulebook (GEN, COB, PIB) | DIFC-authorised firms | Audit trails, immutable logs, access controls, segregation of duties, client asset segregation |
| UAE Central Bank Regulations | Banking customers | Model risk management, validation, documentation, governance per CBUAE guidance |
| ADGM FSRA / DFSA AML Rules | AML/CTF | Customer due diligence, transaction monitoring, SAR filing, record keeping |
| IFRS 9 / IFRS 17 | Financial reporting | Model outputs support impairment, insurance contract calculations |
| Basel III / CRR (via DFSA) | Banking capital | Model risk management, validation, documentation, governance |
6. AI Governance (UAE & DIFC Alignment)
6.1 UAE National AI Strategy 2031
Haqeeba aligns with the UAE’s strategic pillars: responsible AI, governance, talent, infrastructure.
6.2 DIFC AI & Innovation Guidance
We implement model risk management per DFSA/GEN principles: model cards, bias/fairness testing, drift monitoring, human oversight for financial actions, reproducibility, no training on customer data.
6.3 EU AI Act Readiness (for EU-facing customers)
Financial models classified as “high-risk AI systems” (Annex III). We implement: risk management (ISO 14971), data governance, technical documentation, human oversight, accuracy/robustness/cybersecurity testing, post-market monitoring.
6.4 Sector-Specific
- Insurance: DFSA/IAIS alignment — bias testing, explainability
- Banking: DFSA/GEN/PRA model risk management (SR 11-7 equivalent)
- Government: UAE Federal Decree-Law No. 45 of 2021 (Data Protection), NESA standards
7. Compliance Artifacts (Available Under NDA)
| Artifact | Availability | Request |
|---|---|---|
| SOC 2 Type II Report | Customers & prospects | Request |
| ISO 27001 Certificate | Public | Request |
| Penetration Test Summary | Customers (NDA) | Request |
| DPA / SCCs (DIFC-approved) | Contractual | Included in Terms |
| Sub-processor List | Customers | Request |
| BAA (Healthcare) | Enterprise (healthcare) | Request |
| AI Model Cards | Enterprise | Request |
| DFSA/Regulatory Attestations | DIFC-authorised firms | Inquire |
8. Contact
Compliance team: contact@haqeeba.org
For artifact requests, use the Contact form and select “Security & compliance.”
Regulatory inquiries: DIFC Authority, The Gate, DIFC, Dubai — difc.ae