Skip to content
Regional

DIFC & ADGM Reinsurance: Mandatory Technology and Evidence Requirements for Intermediaries

What DFSA and FSRA supervisors inspect during systems reviews of reinsurance intermediaries — local audit trails, record-keeping, sanctions, and evidence architecture.

July 2, 202610 min read
ENAR

Both DIFC (regulated by the Dubai Financial Services Authority) and ADGM (regulated by the Financial Services Regulatory Authority) have positioned themselves as the two dominant regional hubs for international reinsurance broking. The DFSA and FSRA rulebooks reflect that: they set a supervisory bar that is closer to FCA and MAS in substance than to older regional regimes, and they expect intermediaries to operate systems that produce evidence, not just records.

For a reinsurance broker or MGA setting up a desk in Dubai or Abu Dhabi — or expanding an existing operation — the technology and evidence expectations are substantial and often underestimated. This piece is a plain overview of what supervisors actually inspect during systems reviews, so operations and compliance leads can build the right controls in from day one rather than retrofitting them.

The regulatory frame — what the rulebooks require in substance

Both DFSA (COB and GEN modules) and FSRA (COBS and GEN) set out requirements that translate into concrete systems expectations:

  • Adequate record-keeping. Both regimes require intermediaries to maintain records that are sufficient to demonstrate compliance and to allow the regulator to reconstruct transactions. “Sufficient” is judged during a systems review, not by rule.
  • Systems and controls proportionate to the business. Broadly principle-based, but supervisors interpret this against comparable London and Singapore standards.
  • Client money and asset protection. For intermediaries holding client money, controls have to be evidenced not just declared.
  • Anti-money laundering and sanctions screening. Requirements are prescriptive; systems evidence is expected during any supervisory visit.
  • Business continuity and cyber. Increasing focus, particularly since 2024, with specific attention on where data resides and who has access.

What DFSA and FSRA actually inspect during a systems review

Supervisory visits vary in scope, but the systems review portion tends to focus on the same core areas. Below is what a typical visit looks at, based on public rulebook detail and the pattern of intermediary supervision to date.

Transaction reconstruction

Supervisors will pick a sample of placements and ask you to reconstruct them end-to-end: the initial submission, the markets approached, the responses received, the negotiation, the firm order, the closing documentation, the settlement.

The question isn't whether the placement was compliant. The question is whether your systems make the reconstruction possible without heroic effort. If you have to pull together evidence from your placement system, three inboxes, a shared drive, and someone's laptop, you have a records-adequacy problem.

Actor identification

Every action on a placement or claim record must be attributable to a specific, identified user. Shared logins are a serious finding. “System” or “admin” as actor on high-value actions is a finding. Log entries with actor identity that cannot be authenticated (i.e. no login trail) are a finding.

Data residency and access

Where does client and placement data physically reside? Who can access it? What's the physical and logical separation between UAE-hosted infrastructure and infrastructure in other jurisdictions? These questions are asked more often than most intermediaries expect, especially of firms using cloud infrastructure with default regions in Europe or North America.

This is where the “US SaaS with an EU region option” model is running into friction. Regional supervisors increasingly want to see architectural separation, not just region selection. See our EU sovereignty page for the broader pattern (which the UAE regime is converging with).

Sanctions and financial crime

Every party to a placement — insured, reinsured, coinsurer, panel member — must be screened. Timing matters: at inception, at renewal, and at any material change. Supervisors will ask for the screening evidence on a sample of placements, and they will look at both the timestamp and the list version screened against.

The lists that must be screened against include the UAE Cabinet Decision list, UN Security Council consolidated list, OFAC (where dollar-denominated), OFSI (for UK-linked business), EU consolidated list, and any list specifically flagged by the DFSA or FSRA. Manual screening against a screenshot from six months ago is not evidence of compliance.

Client money and settlement controls

For intermediaries holding client money, the systems review will examine the segregation, reconciliation, and settlement controls in detail. Automated reconciliation with same-day exception reporting is now the expected baseline for any intermediary of scale.

Business continuity and cyber

BCP and cyber controls are inspected against ISO 27001 or equivalent as a de-facto benchmark. Recovery point and time objectives are asked for and tested. Incident response documentation and evidence of tabletop exercises are expected.

The specific systems posture that survives a review

For a reinsurance intermediary operating from DIFC or ADGM, the systems posture that consistently satisfies supervisors has these characteristics:

  • A placement platform where the placement lives — not a system of record with the real work happening in email. Threaded communication, capacity tracking, firm order confirmation, and closing documentation all attached to the placement record with full audit trail. See facultative workflow automation.
  • Structured, per-counterparty document generation — closing slips, cover notes, endorsements generated from the placement record with template enforcement, not Word merges. See why closing documentation quality is a supervisory signal.
  • Sanctions screening built into the workflow — automated screening at binding, at renewal, and at any material change, with list version and timestamp captured for every check.
  • Immutable, cryptographically verifiable audit trail — every action attributed to an identified user with a server-side timestamp, and the log itself protected against modification. This is now the effective baseline for what supervisors mean by “adequate records.” See how immutable audit trails work.
  • Data residency architecture, not just a region setting — clear architectural documentation of where data resides, who has access, and how UAE data is separated from data flows to other jurisdictions.
  • Documented, tested BCP and incident response — with evidence of testing, not just documentation of intent.

What the shift from ldquo;good enough” to ldquo;supervisor-ready” costs

The intermediaries we see spending the most on remediation are the ones who deferred the systems investment during the setup phase. Retrofitting audit trails into a legacy placement system is expensive; retrofitting sanctions integration into a manual workflow is expensive; retrofitting proper data residency into a cloud footprint that was provisioned without it is expensive.

Building it right at the start of the DIFC or ADGM setup is measured in weeks, not months. The trade-off is that it requires committing to a modern operational stack rather than replicating what was in place at the parent company's London office.

Regional context — where UAE supervision is heading

Both DFSA and FSRA are on a supervisory maturity curve. The direction of travel — more systems inspection, more evidence expectation, more attention to data residency and cyber — mirrors what happened in London over 2019 to 2024. Intermediaries planning long-term presence should build to the expected 2027 supervisory standard, not the 2025 one.

For a broader view of Middle East regulatory expectations across insurance and reinsurance, see the Middle East solutions page. For related content, see SAMA compliance for digital insurance platforms.

Bottom line

DIFC and ADGM are not lighter-touch jurisdictions. They are hub jurisdictions with hub-level supervisory expectations, and the systems bar is closer to London than to older regional regimes. Reinsurance intermediaries who build to that bar from day one — placement platform, sanctions integration, audit trail, data residency — pass systems reviews as a matter of routine. Those who don't spend the following 18 months in remediation.

Fatima Al-HasanInsurance Operations Lead, Middle East
Fatima leads Regure’s Middle East insurance practice, covering SAMA cybersecurity framework alignment, CBUAE Open Finance APIs, Takaful claims processing, and Arabic-English bilingual operations across the GCC.

Ready to modernize your claims operations?

Book a 20-minute demo and see how Regure automates the manual work holding back your team.

Book a Demo