Audit & Assurance · Internal & Operational Audits
Compliance Audit
A UAE business today answers to more regulatory regimes at once than at any point in its history — VAT and Corporate Tax filings with the Federal Tax Authority, WPS payroll discipline with MOHRE, AML/CFT obligations under Cabinet Decision No.
Chartered Accountants · Dubai · Since 1986
A compliance audit is an independent examination of whether an organisation's policies, records, and day-to-day operating practices actually satisfy the specific laws, regulations, licence conditions, and contractual obligations that apply to it. It differs from a statutory financial audit, which opines on whether the financial statements present a true and fair view, and from a broader internal audit, which covers the full spectrum of operational and financial controls. A compliance audit is narrower and more targeted: it takes a defined set of regulatory or contractual obligations — VAT filing accuracy under Federal Decree-Law No. 8 of 2017, Corporate Tax positions under Federal Decree-Law No. 47 of 2022, WPS payroll compliance with MOHRE, AML/CFT programme adequacy under Cabinet Decision No. 10 of 2019, free zone authority licence conditions, or a specific regulator's rulebook — and tests, obligation by obligation, whether the business can produce evidence that it is meeting each one.
In the UAE, the compliance landscape a business must navigate depends heavily on its licensing jurisdiction and sector. A DMCC or JAFZA trading company faces FTA obligations (VAT registration and filing, Corporate Tax registration and, where applicable, filing), MOHRE and WPS payroll rules, and its free zone authority's own licence renewal and reporting conditions. A DIFC or ADGM entity regulated by the DFSA or FSRA carries additional prudential, conduct, and reporting obligations under that regulator's rulebook. A Designated Non-Financial Business or Profession — real estate brokers and agents, dealers in precious metals and stones, and independent legal or accounting professionals providing specified services, among others — carries AML/CFT obligations including customer due diligence, suspicious transaction reporting, and registration on the goAML platform maintained by the UAE Financial Intelligence Unit. A compliance audit is scoped to the specific combination of obligations that actually apply to the entity under review, rather than a generic checklist copied across every client regardless of licence type or sector.
The obligation set a compliance audit tests also depends heavily on whether the entity is licensed on the mainland or in a free zone, and that distinction runs through almost every category of obligation, not just Corporate Tax. A mainland business trading directly with UAE-based customers or importing goods carries VAT and customs-linked reporting nuances that a free zone entity dealing only with parties outside the UAE may not carry in the same way. A JAFZA or DMCC company relying on the 0% Corporate Tax rate on qualifying income as a Qualifying Free Zone Person under Federal Decree-Law No. 47 of 2022 must be able to evidence, on an ongoing transactional basis, that its qualifying activities and de minimis thresholds are actually being tracked — not simply assumed to hold because the original free zone licence category once qualified. A mainland company has no equivalent qualifying-income test to satisfy, but sits inside the standard Corporate Tax regime without a free zone carve-out to manage, so the documentation a compliance audit expects to see differs meaningfully between the two structures even within the same group. An offshore holding vehicle — a RAK ICC or JAFZA offshore company that does not hold a trading licence and does not conduct business inside the UAE — typically carries a much narrower obligation set again, generally limited to registered agent, beneficial ownership, and annual return conditions rather than VAT, WPS, or a trading Corporate Tax profile, and a compliance audit scoped for such a vehicle should not be padded with obligations that simply do not attach to it.
Economic Substance Regulations (ESR) notification and report filing obligations, introduced under Cabinet Decision No. 57 of 2020, applied to UAE mainland and free zone entities carrying out defined 'relevant activities' for financial years ending before 1 January 2023; ESR requirements were discontinued for financial years starting on or after that date under Cabinet Decision No. 98 of 2024. A compliance audit covering a historical period before the cut-off may still need to test ESR filing evidence, but for current and future financial years it is a closed compliance chapter rather than a live obligation, and PNPC flags this distinction at scoping stage so budget is not spent testing something that has already lapsed.
Where scope extends into workforce compliance beyond WPS payroll timing, a compliance audit can also test visa administration against General Directorate of Residency and Foreign Affairs (GDRFA) and Federal Authority for Identity, Citizenship, Customs & Port Security (ICP) requirements, and, where relevant to the entity's size, whether Emiratisation obligations administered through MOHRE's Nafis programme are being monitored on schedule. For UAE Central Bank-regulated entities — exchange houses, finance companies, payment service providers — the obligation set expands further to the Central Bank's own prudential and conduct rulebook, tested alongside the FTA, MOHRE, and AML/CFT obligations most UAE businesses carry.
The distinguishing feature of a proper compliance audit is that it tests evidence, not assertions. A VAT compliance audit does not stop at confirming a VAT registration certificate exists — it reconciles filed EmaraTax returns against the general ledger, tests input VAT recoverability decisions on a sample of transactions, and checks whether reverse-charge and zero-rating positions are documented and defensible. An AML/CFT compliance audit does not stop at confirming a policy document exists — it samples actual customer files for evidence that due diligence was performed and documented at onboarding, tests whether the risk-based approach is genuinely being applied, and checks whether any suspicious activity indicators were escalated and reported through the correct channel rather than quietly ignored. A WPS compliance audit reconciles the payroll register against actual WPS submission records and salary transfer timing, not just the existence of a payroll policy.
What drives cost and timeline variance across engagements is rarely the number of obligation categories alone — it is headcount (which drives the volume of payroll and visa records to sample), the number of legal entities in scope (each entity typically needs its own obligation map, not a shared one), whether customer due diligence files need to be sampled for a DNFBP, and how current the client's own records are when fieldwork starts. A single-entity, single-obligation review with well-organised records can be scoped tightly; a multi-entity group spanning mainland, free zone, and DIFC/ADGM licences with a DNFBP designation in one entity requires materially more fieldwork time regardless of how the fee is ultimately structured.
Compliance audits are typically commissioned for one of several reasons: as a proactive, board-driven health check ahead of a licence renewal, bank facility renewal, or investor due diligence process; in response to a specific trigger such as an FTA query, a regulator's information request, or a near-miss compliance incident; as a periodic exercise for entities in higher-risk categories (DNFBPs, DIFC/ADGM regulated firms); or as a condition written into a bank covenant, franchise agreement, or investor term sheet. Unlike a one-off internal controls health check, a compliance audit is anchored specifically to named legal and regulatory obligations, which means the findings map directly to identifiable exposure — a missed WPS deadline, an under-documented related-party transaction, a customer file with no evidenced due diligence — rather than a general commentary on control maturity.
The output is a findings report that identifies each tested obligation, the evidence reviewed, whether the obligation is being met, and — where it is not — the specific gap, its risk rating, and a recommended remediation step with an owner and target date. Because compliance gaps often carry direct penalty or licence-renewal exposure rather than purely reputational risk, PNPC prioritises findings by regulatory exposure first and operational inconvenience second, and flags any gap serious enough to warrant an immediate voluntary disclosure or corrective filing rather than waiting for the final report to be issued.
Compliance audit vs related assurance engagements in the UAE
| Feature | Compliance Audit | Internal Audit | Statutory (External) Audit | Forensic/Fraud Investigation |
|---|---|---|---|---|
| Primary purpose | Test whether specific named legal/regulatory obligations are being met, with evidence | Independent assurance on risk management, controls and governance broadly | Opinion on true and fair view of financial statements | Investigate a specific suspected irregularity for evidentiary/legal use |
| Scope anchor | Named laws, regulator rulebooks, licence conditions, or contractual obligations | Risk-ranked audit universe across financial, operational, IT and compliance processes | Financial statements and supporting records | The specific transaction, individual, or process in question |
| Who it reports to | Management, audit committee, or board depending on trigger | Audit committee / board | Shareholders (via signed audit report) | Board / legal counsel / regulator, often under privilege |
| Mandatory under UAE law | Not generally mandatory as a standalone exercise, though the underlying obligations tested (VAT, WPS, AML/CFT for DNFBPs) are themselves mandatory | Not generally mandatory for mainland/most free zone entities; often required for DIFC/ADGM regulated firms and bank covenants | Yes — annual filing typically required by DED/free zone authority licence conditions | No — triggered by a specific event |
| Typical trigger | Licence/facility renewal, DNFBP status, regulator query, new tax registration, M&A due diligence | Board decision, investor/lender condition, regulatory expectation | Annual licence renewal condition | Whistleblower report, unexplained loss, suspicious transaction |
| Typical output | Obligation-by-obligation findings report with risk rating and remediation plan | Findings report with risk ratings, root cause and management action plan across a broader control universe | Signed audit opinion and financial statements | Investigation report, evidence file, possible referral to authorities |
| Relevant UAE bodies | FTA, MOHRE, free zone authority, DFSA/FSRA, UAE FIU (goAML) | DFSA (DIFC), FSRA (ADGM), free zone authority governance codes, bank covenants | DED / free zone licensing authority, FTA (for tax-linked disclosures) | Dubai Courts / DIFC Courts / ADGM Courts if litigation follows; goAML if AML-related |
| Frequency | Periodic, proportionate to risk profile — often aligned to licence renewal or governance calendar | Annual cycle, quarterly reviews, or continuous co-sourced function | Annual, tied to financial year end | Ad hoc, triggered by an incident |
| Independence requirement | Independent of the function/obligation being tested; reports outside the team responsible for the obligation | Independent of the function being reviewed; ideally independent of the external auditor | Independent registered auditor, distinct from internal audit | Fully independent, often litigation-ready methodology |
Compliance audit and internal audit frequently overlap in practice — many PNPC engagements combine a compliance-obligation review with a broader controls assessment in a single scoping exercise. The right structure depends on whether the driver is a specific regulatory obligation set or a broader governance question; a scoping conversation with a PNPC partner clarifies which framing fits your situation.
| Stage | What Happens | Who Acts | Typical Output | Timeframe | Common Pitfall |
|---|---|---|---|---|---|
| 1. Obligation Mapping | Identify every regulatory and contractual obligation genuinely applicable to the entity — licence type, tax registrations, DNFBP status, regulator category, contractual reporting duties | PNPC partner, with management input on licences and registrations held | A scoped obligation universe specific to this entity, not a generic checklist | Day 1–3 of engagement | Relying on management's verbal list of registrations instead of verifying it against primary FTA, MOHRE, and free zone authority records directly |
| 2. Risk Prioritisation | Rank obligations by exposure — penalty risk, licence-renewal risk, reputational risk — and by evidence of recent change (new registration, new hires, new activity) | PNPC engagement lead | A risk-ranked scope for fieldwork, agreed with management or the audit committee | Day 2–4 | Prioritising by perceived severity rather than actual penalty and licence-renewal exposure, leading to fieldwork time spent on lower-risk items first |
| 3. Engagement Letter & Access Arrangements | Formalise scope, fee, timeline, and confidentiality terms; agree what records, filings, and system access will be provided | PNPC and client signatory | Signed engagement letter and an access/document request list | Day 3–5 | Starting fieldwork before access arrangements are formally agreed, causing later disputes over what records were meant to be provided |
| 4. Document & Filing Review | Collect and review filed returns (VAT, Corporate Tax), WPS records, AML/CFT policy and customer files, licence and registration certificates, and prior regulator correspondence | PNPC fieldwork team, supported by client finance/compliance staff | A populated evidence file mapped against each obligation tested | Week 1–2 | Accepting a summary schedule prepared by the client's own finance team instead of pulling the underlying filed returns and portal records directly |
| 5. Sample Testing | Test a sample of transactions, customer files, or payroll runs against the underlying obligation — not just confirm a policy exists | PNPC fieldwork team | Testing workpapers evidencing whether each obligation is met in practice | Week 2–3 | Sampling only recent transactions and missing a systemic issue that only shows up in an earlier period |
| 6. Gap Identification & Root Cause | Where testing reveals a gap, determine whether it is a one-off error or a systemic process weakness, and rate the risk | PNPC engagement lead | Draft findings list with risk ratings and preliminary root cause | Week 3 | Recording a finding without distinguishing a one-off clerical error from a systemic process weakness, which misdirects the remediation plan |
| 7. Management Discussion | Walk draft findings through with process owners to correct factual errors and agree realistic remediation timelines | PNPC and named process owners | Agreed factual findings and draft remediation commitments | Week 3–4 | Softening or removing a finding under pushback rather than documenting a genuine factual correction separately from an unresolved disagreement |
| 8. Final Report | Issue the obligation-by-obligation findings report with risk ratings, evidence summary, and recommended remediation actions | PNPC partner presents to management or the board | Final compliance audit report with a management action plan | Week 4 | Issuing a report with no named remediation owner or committed date, so agreed actions are never actually tracked to completion |
| 9. Urgent Escalation Where Needed | Any gap serious enough to warrant an immediate voluntary disclosure or corrective filing is flagged and escalated before the final report is finished, not held until the end | PNPC partner and client's tax/legal advisor | Immediate notification memo where applicable | As soon as identified, ahead of the final report | Holding a serious filing error or AML/CFT gap for the final report instead of escalating immediately, losing the benefit of an earlier voluntary disclosure |
| 10. Remediation Follow-Up | Track agreed remediation actions and, where appropriate, re-test previously flagged obligations after a defined period | PNPC, reporting to management or audit committee | Follow-up confirmation of remediation status | Typically 60–120 days after report issuance | Treating management's assertion that remediation occurred as sufficient, without re-testing the underlying evidence |
| 11. Coordination with Statutory Auditor / Tax Advisor | Where useful and with management's consent, share relevant compliance audit findings with the client's external auditor or tax advisor to avoid duplicated testing and align on any filing implications | PNPC engagement lead and client's existing advisors | Reduced duplication of effort and consistent messaging across advisors | Ongoing through the engagement | Sharing findings informally without management's explicit consent, creating confusion over which advisor owns which follow-up action |
| 12. Cycle Refresh for Structural Change | Where the entity adds a new registration, jurisdiction, DNFBP designation, or regulator category, refresh the obligation map ahead of the next compliance audit cycle | PNPC engagement lead, with management input | An updated obligation universe reflecting the business as it stands today | At the point of the structural change, ahead of the next scheduled cycle | Waiting for the next scheduled compliance audit cycle to capture a new registration or jurisdiction instead of refreshing the obligation map when the change actually happens |
| 13. Data Room / System Access Provisioning | The client provisions read-only access to EmaraTax, WPS portal extracts, and internal accounting or HR systems as agreed in the access arrangements | Client IT/finance team, PNPC fieldwork team | Confirmed access credentials and a system access log retained in the engagement file | Week 1 | Read-only access granted late in the engagement compresses the sample-testing window without the timeline itself being extended to match |
| 14. Sampling Plan Design | PNPC designs a risk-weighted, defensible sample of transactions, customer files, or payroll runs for each obligation in scope, rather than testing every record or an arbitrary handful | PNPC engagement lead | A documented sampling methodology and rationale retained in the engagement workpapers | Week 1–2 | An undocumented or ad hoc sample size that cannot be defended if a finding is later challenged by the client or a regulator |
| 15. Interim Findings Briefing | A short interim briefing is given to management partway through fieldwork, surfacing any early or urgent findings before the draft report stage | PNPC engagement lead and named management contact | An interim findings memo distinct from the final report | Midpoint of fieldwork, typically Week 2–3 | Treating the interim briefing as optional and only communicating findings at the very end, losing time that could have been used to start remediation early |
| 16. Draft Report Circulation for Factual Accuracy | A draft report is circulated to named process owners specifically to check factual accuracy — figures, dates, named individuals — before risk ratings are finalised | PNPC engagement lead and process owners | A factually verified draft report ready for risk-rating finalisation | Week 4 | Conflating a factual-accuracy check with an invitation to renegotiate the substance of a finding, which can quietly dilute the report if not managed carefully |
| 17. Board / Audit Committee Presentation | Where the engagement was commissioned by the board or audit committee rather than management alone, the final report is presented directly to that body | PNPC partner | Board or audit committee minutes recording the presentation and any resulting resolutions | Within 1–2 weeks of the final report | Findings reaching the board only in summarised form through management, diluting the board's ability to challenge and own the remediation plan directly |
| 18. Confidentiality & Report Distribution Controls | Distribution of the final report — internally and to any third party such as a bank or investor — is agreed explicitly with the client rather than assumed | PNPC and client signatory | A written record of who received the report and under what confidentiality terms | At final report issuance | A report shared informally with a lender or investor without first agreeing the scope of reliance, creating exposure if the reader relies on it beyond its intended purpose |
| 19. Post-Engagement Advisory Availability | PNPC remains available for a defined period after the final report to answer follow-up questions from management, the board, or the client's other advisors on the findings | PNPC engagement lead | Follow-up queries resolved without needing a separate re-engagement | Typically 30 days post-report, as agreed in the engagement letter | Assuming unlimited free post-report support is included by default rather than confirming what is and is not covered in the original fee |
| 20. Archiving of Workpapers & Evidence | Engagement workpapers, evidence samples, and correspondence are archived in line with PNPC's retention policy, supporting any future re-testing or regulator query | PNPC engagement team | An archived engagement file retrievable for future reference or follow-up testing | Within 30 days of final report issuance | Workpapers not properly archived make follow-up testing or a later regulator query far harder to respond to with confidence |
A single-obligation compliance audit (for example, a focused VAT or WPS compliance review) can often be completed in a few weeks once records are made available. A multi-obligation review spanning tax, payroll, and AML/CFT for a DNFBP, or a review across a multi-entity group, typically takes longer given the volume of filings and customer files to sample. PNPC agrees a specific timeline in the engagement letter once scope is confirmed.
Trade licence(s) for each UAE entity in scope — mainland DED licence and/or free zone authority licence (JAFZA, DMCC, RAKEZ, IFZA, Meydan, ADGM, DIFC, RAK ICC, Ajman)
Certificate of incorporation, Memorandum/Articles of Association, and shareholder register
Any franchise, agency, distribution, or facility agreement containing specific compliance reporting obligations to a third party
Correspondence log with the licensing authority, FTA, MOHRE, or sector regulator over the past 12–24 months
Licence activity code listing, checked against the entity's actual operating activity, since operating outside a licensed activity scope is itself a compliance gap
VAT registration certificate (Tax Registration Number) and filed VAT returns for the review period, with supporting reconciliations
UAE Corporate Tax registration and, where applicable, the Corporate Tax return, related-party transaction schedules, and Qualifying Free Zone Person qualifying-income analysis
EmaraTax portal filing confirmations and any FTA correspondence, queries, or assessment notices
Records supporting reverse-charge, zero-rating, or exemption positions taken on VAT returns, where relevant to the entity's activity
Import/customs documentation supporting any import VAT or reverse-charge positions, for entities that import goods
Payroll register and Wage Protection System (WPS) submission records for the review period
Employment contracts sample, visa/work-permit records, and MOHRE correspondence including any prior penalties or restrictions
Salary transfer timing evidence reconciled against WPS submission and payment records
WPS Salary Information File (SIF) confirmations from the paying bank or exchange house, evidencing that a submitted file was actually accepted and processed, not just generated
AML/CFT policy and procedures manual, and evidence of board or senior management approval
goAML registration confirmation and any suspicious transaction reports filed
Sample of customer due diligence files evidencing onboarding checks, risk rating, and periodic review
AML/CFT training records for relevant staff
Records evidencing the designated Money Laundering Reporting Officer's appointment and ongoing activity, where a DNFBP designation applies
DFSA or FSRA licence and category confirmation, and the applicable rulebook provisions relevant to the entity's category
Prudential or conduct reporting submissions made to the regulator over the review period
Any regulator supervisory visit findings, correspondence, or open action items
Signed engagement letter defining scope, obligations tested, fee, and confidentiality terms
Access arrangements — read-only system access, filing portal access where relevant, and named liaison contacts for each obligation area
Confirmation of who receives the final report and owns the resulting management action plan
Employee visa status listing and quota utilisation records against GDRFA/ICP requirements for the review period
Emiratisation quota tracking and reporting evidence through MOHRE's Nafis programme, where applicable to the entity's size and sector
Visa renewal and cancellation processing logs, showing timing against permit expiry dates
Group structure chart showing all UAE and non-UAE entities in scope, ownership percentages, and intercompany relationships
Intercompany agreements (management fees, cost-sharing, loans) and supporting transfer pricing documentation
Related-party transaction schedules as disclosed or supporting the Corporate Tax related-party position for each entity in scope
Prior statutory (external) audit report and management letter, where one exists, for context on previously flagged control weaknesses
Prior internal audit or compliance audit reports and their remediation status, so the current cycle can confirm whether earlier findings actually closed
Any FTA, MOHRE, free zone authority, or sector-regulator penalty notices, assessment orders, or formal warnings issued in the past three years
Read-only access credentials or extracts from EmaraTax, the WPS portal, and internal accounting or HR/payroll systems, as agreed in the access arrangements
A system access log documenting who provisioned access and when, retained in the engagement file for audit trail purposes
Confirmation of the data extract methodology used for any bulk records pulled for sample testing, so testing conclusions can be traced back to source
| Phase | Triggered By | PNPC Compliance Audit Approach | Risk If Ignored |
|---|---|---|---|
| Initial Obligation Mapping | Board decision, licence renewal, or a specific trigger event | Build the obligation universe specific to the entity's licence type, registrations, and sector, and agree the scope with management | Testing against a generic checklist instead of the entity's actual obligations wastes budget and can miss the obligation that matters most |
| First Compliance Audit Cycle | Scope agreed | Test the highest-risk obligations first — typically VAT/Corporate Tax filing accuracy, WPS compliance, and AML/CFT programme adequacy where DNFBP-relevant | Deferring the review until a regulator query arrives removes the opportunity to self-correct before enforcement attention |
| Findings & Remediation Agreement | Fieldwork complete | Discuss draft findings with process owners, agree risk ratings and root cause, and set remediation owners and dates | Findings not discussed and agreed with process owners are more easily disputed or ignored during remediation |
| Urgent Gap Escalation | A serious compliance gap is identified during fieldwork | Escalate immediately to management and, where appropriate, recommend a voluntary disclosure to the FTA via EmaraTax rather than waiting for the final report | Sitting on a known filing error until the final report is issued delays a voluntary disclosure that is typically viewed more favourably the sooner it is made |
| Remediation Tracking | Final report issued | Track agreed remediation actions against committed dates and escalate overdue items to management or the audit committee | Findings reported but never followed up leave the underlying regulatory exposure live |
| Follow-Up Testing | After remediation deadlines pass | Re-test the specific obligations previously flagged to confirm remediation actually occurred, not just that a policy was updated | Unverified remediation frequently turns out to be partial when re-tested |
| Regulatory or Structural Change | New tax registration, new DNFBP designation, new regulator category, new jurisdiction added to group | Refresh the obligation map and re-scope the next compliance audit cycle to reflect the change | An obligation map that does not evolve with the business tests yesterday's requirements while missing new ones just taken on |
| Annual or Periodic Cycle Renewal | Licence renewal date, regulator's own review cycle, or board decision | Repeat the compliance audit on a periodic basis proportionate to the entity's risk profile, refreshing scope each cycle | Treating compliance audit as a one-off exercise loses the year-on-year comparability that shows whether remediation is holding |
| Group or Licensing Structural Change | New free zone entity added, new Central Bank or DFSA/FSRA licence category, new jurisdiction added to the group | Refresh the obligation map for the affected entity and re-scope the next compliance audit cycle to reflect the new licence-specific conditions | An obligation map that does not track a new entity or licence category tests yesterday's structure while missing the new obligations just taken on |
| Cross-Border Group Consolidation | A UAE entity's related-party transactions with an overseas parent or subsidiary grow in volume or complexity | Extend related-party and transfer pricing documentation testing across the cross-border relationship, coordinating with any overseas advisor involved | Related-party documentation reviewed only on the UAE side can miss inconsistencies with how the same transaction is recorded overseas |
| Wind-Down or Exit Preparation | Board decision to close, sell, or de-register a UAE entity | Run a final-cycle compliance audit ahead of licence cancellation or sale, confirming all obligations are current so closure or completion is not delayed by an unresolved gap | An unresolved compliance gap surfacing during licence cancellation or a buyer's confirmatory review can delay or reduce the value of an otherwise straightforward exit |
Testing against a generic obligation checklist instead of the entity's actual licence type, registrations, and sector — missing the obligation that matters most while wasting budget on ones that don't apply
Treating Economic Substance Regulations as a still-live current-period obligation when notification and reporting requirements were discontinued for financial years starting on or after 1 January 2023
Assuming Qualifying Free Zone Person status holds because the original free zone licence category once qualified, without evidencing qualifying income and de minimis thresholds each period
Scoping a mainland-plus-free-zone group under one uniform obligation set rather than mapping each licensed entity's distinct VAT, Corporate Tax, and licence-specific conditions separately
Starting fieldwork before the engagement letter and access arrangements are agreed, leading to disputes later over what records were meant to be provided
Applying a full trading-entity obligation checklist to a pure offshore holding vehicle or a non-trading holding company, testing obligations that were never triggered by its actual activity
Accepting that an AML/CFT policy document exists as proof of compliance, without sampling actual customer due diligence files for evidenced onboarding and periodic review
Reconciling WPS submissions to the payroll policy rather than to actual salary transfer timing records and the bank's SIF acceptance confirmation, which is what MOHRE ultimately tests
Relying on a related-party transaction being described consistently across entities without checking the underlying intercompany agreements and transfer pricing documentation actually match
Treating a filed VAT or Corporate Tax return as self-evidencing, without reconciling it back to the general ledger and underlying transaction records
Overlooking contractual compliance obligations owed to a franchise principal, licensor, or lender because the review focused only on statutory and regulatory obligations
Using an undocumented or ad hoc sample size for testing, leaving no defensible rationale if a finding is later challenged by the client or a regulator
Holding a serious filing error or AML/CFT gap for the final report instead of escalating it immediately, losing the benefit of an earlier voluntary disclosure or corrective filing
Issuing findings with no named remediation owner or committed date, so agreed actions never get tracked to completion
Never re-testing previously flagged obligations after the remediation deadline, so a control 'closed' on paper can quietly reopen without anyone noticing
Treating a compliance audit as a one-off exercise rather than a periodic cycle, losing the year-on-year comparability that shows whether remediation actually held
Sharing a compliance audit report with a lender, investor, or JV counterparty without first agreeing the scope of reliance, creating exposure if the third party relies on it beyond its intended purpose
Is a compliance audit a legal requirement for UAE companies?
There is no single federal law mandating a standalone 'compliance audit' for every UAE company. What is mandatory are the underlying obligations a compliance audit tests — VAT and Corporate Tax filing where registered, WPS payroll compliance, and AML/CFT programme requirements for Designated Non-Financial Businesses and Professions. DIFC and ADGM regulated entities may face additional DFSA or FSRA reporting expectations. The compliance audit itself is typically a voluntary, proactive exercise commissioned by the board or driven by a lender, investor, or licence-renewal requirement.
How is a compliance audit different from a statutory (external) audit?
Statutory audit expresses an opinion on whether the financial statements present a true and fair view, for shareholders and the licensing authority. A compliance audit is narrower and obligation-specific — it tests whether named regulatory requirements (VAT accuracy, WPS timeliness, AML/CFT programme adequacy) are being met in practice, independent of whether the financial statements as a whole are fairly presented. A company can pass its statutory audit and still have live compliance gaps a compliance audit would surface.
How is a compliance audit different from an internal audit?
Internal audit is broader — it covers financial, operational, IT, and compliance risk across a risk-ranked universe of processes, reporting to the audit committee or board on the overall control environment. A compliance audit is anchored specifically to named legal, regulatory, or contractual obligations and tests whether each is being met, obligation by obligation. In practice the two often overlap, and many PNPC engagements combine elements of both depending on what the client actually needs.
What obligations does a typical UAE VAT compliance audit test?
A VAT compliance audit reconciles filed EmaraTax VAT returns against the general ledger, tests a sample of input VAT recovery decisions for correct classification, checks that output VAT has been correctly charged and reported on relevant supplies, and reviews the documentation supporting any zero-rated, exempt, or reverse-charge positions taken. It is testing under Federal Decree-Law No. 8 of 2017 and current FTA guidance, applied to the entity's actual transaction records rather than a general commentary on VAT awareness.
Does a compliance audit cover Corporate Tax under Federal Decree-Law No. 47 of 2022?
Yes, where the entity is registered for Corporate Tax. We test whether the Tax Registration Number is current, whether related-party transactions are properly documented and priced on an arm's-length basis where the related-party rules apply, and — for free zone entities claiming the 0% rate on qualifying income — whether the conditions for Qualifying Free Zone Person status are being tracked and evidenced on an ongoing basis rather than assumed. Corporate Tax applies at 0% on taxable income up to AED 375,000 and 9% above that threshold for standard taxpayers, effective for financial years starting on or after 1 June 2023.
What is WPS and why is it a compliance audit focus area?
The Wage Protection System (WPS) is the electronic salary transfer system mandated by the Ministry of Human Resources and Emiratisation (MOHRE) to track timely, accurate payment of wages through registered UAE banks or exchange houses. A compliance audit reconciles the payroll register against actual WPS submission records and salary transfer timing, since non-compliance can trigger MOHRE penalties and, in serious or repeated cases, restrictions on a company's ability to process new work permits.
Who needs an AML/CFT compliance audit as a Designated Non-Financial Business or Profession (DNFBP)?
Certain UAE businesses — including real estate brokers and agents, dealers in precious metals and stones, and independent legal or accounting professionals providing specified services, among others — fall within the DNFBP category under Cabinet Decision No. 10 of 2019 and must maintain AML/CFT policies, perform customer due diligence, and register on the goAML platform maintained by the UAE Financial Intelligence Unit. A compliance audit tests whether these controls are genuinely operating — sampling actual customer files for evidenced due diligence, not just confirming the policy document exists.
Can a compliance audit help before a bank facility or licence renewal?
Yes. Lenders increasingly build compliance representations into facility agreements, and free zone authorities require current licence and filing status for renewal. A compliance audit run ahead of the renewal date identifies and helps remediate gaps — a lapsed filing, an outdated registration detail, an unresolved MOHRE query — before the renewal process itself surfaces them and creates delay or additional scrutiny.
Does a compliance audit cover DIFC or ADGM regulatory obligations specifically?
Yes, for entities regulated by the DFSA (DIFC) or FSRA (ADGM), a compliance audit can be scoped to test the specific rulebook provisions applicable to that firm's licence category — prudential reporting, conduct requirements, and any client-money or capital-adequacy conditions relevant to the category held. This is scoped in close coordination with the client's existing regulatory advisor where one exists, to avoid duplicating specialist regulatory compliance work already underway.
What happens if a compliance audit finds a filing error already submitted to the FTA?
We flag this immediately rather than waiting for the final report, and recommend the client's tax advisor assess whether a voluntary disclosure via the EmaraTax portal is the appropriate corrective step, given that timely voluntary disclosure is generally treated more favourably than an error later identified through an FTA audit or enforcement action.
How long does a UAE compliance audit take?
A focused single-obligation review — for example, WPS compliance alone, or a VAT filing accuracy review — can often be completed within a few weeks once records are made available. A multi-obligation review spanning tax, payroll, and AML/CFT for a DNFBP, or a review across several legal entities in a group, takes longer given the volume of filings and customer files that need to be sampled. PNPC confirms a specific timeline in the engagement letter once scope is agreed rather than quoting a generic figure.
Is the fee for a compliance audit fixed or variable?
PNPC agrees a fixed fee for each defined compliance audit engagement, confirmed in writing before fieldwork begins. Fee depends on the number of obligations in scope, the number of legal entities under review, and the volume of records and customer files that need to be sampled — a single-obligation review costs meaningfully less than a multi-obligation review across a group structure.
Can compliance audit findings trigger a broader internal audit or forensic review?
Yes. A compliance audit occasionally surfaces a finding that points to a broader control weakness beyond the specific obligation tested — for example, a pattern of vendor master changes surfacing during a VAT input-recovery sample that suggests a wider procurement control gap, or a customer due diligence gap that raises a fraud-risk concern. Where that happens, we recommend escalating to a broader internal audit or, where a specific irregularity is suspected, a dedicated forensic investigation with a different evidentiary standard.
Does PNPC coordinate with our existing tax advisor or auditor during a compliance audit?
Yes, with management's consent. Where a client already has a tax advisor handling VAT and Corporate Tax filings, or an external statutory auditor, we coordinate to avoid duplicated testing and to make sure any compliance audit finding relevant to an upcoming filing or audit is flagged to the right advisor promptly.
Can PNPC run a compliance audit across both our UAE and Indian entities?
Yes. PNPC operates from offices in the UAE (Dubai) and India (Chennai, Bangalore, Hyderabad), and for groups with cross-border structures we run compliance audits that specifically test related-party transaction documentation and transfer pricing consistency across both jurisdictions under one coordinated engagement, rather than splitting the review between two disconnected advisors.
Why engage PNPC rather than a generic compliance-checklist provider?
PNPC scopes every compliance audit from an obligation map specific to the entity's actual licence type, registrations, and sector — not a templated checklist applied regardless of what genuinely applies. Our findings are backed by sample testing against actual filings, payroll records, and customer files, not assertions that a policy exists. We escalate serious gaps immediately rather than holding them for a final report, and we track remediation to completion rather than treating the report as the end of the engagement.
Can a compliance audit be scoped to just one obligation, like WPS alone?
Yes. A compliance audit does not have to cover every obligation category at once — a single-obligation review focused only on WPS payroll compliance, or only on VAT filing accuracy, is a common and proportionate scope where management has a specific concern rather than a full-spectrum review need. The obligation-mapping step at the start of any engagement is what determines whether a narrow or broad scope is the right fit.
Does a compliance audit test Qualifying Free Zone Person conditions specifically?
Where a free zone entity claims the 0% Corporate Tax rate on qualifying income as a Qualifying Free Zone Person under Federal Decree-Law No. 47 of 2022, a compliance audit tests whether qualifying activities and any applicable de minimis thresholds are being tracked on an ongoing transactional basis and evidenced, rather than assumed to hold simply because the entity's original free zone licence category once qualified.
How does a compliance audit differ for a mainland company versus a free zone company?
The obligations tested differ in emphasis, not just detail. A mainland business trading directly with UAE-based customers or importing goods carries VAT and customs-linked reporting nuances a free zone entity dealing only with parties outside the UAE may not carry in the same way, while a free zone entity claiming Qualifying Free Zone Person status carries an ongoing qualifying-income tracking obligation a mainland company does not have. A compliance audit scoped for a mainland-plus-free-zone group tests both profiles separately rather than applying one generic obligation set across every entity.
Does a compliance audit cover Economic Substance Regulations (ESR)?
ESR notification and report filing obligations were discontinued for financial years starting on or after 1 January 2023, under Cabinet Decision No. 98 of 2024. For current and future financial years, ESR is not a live, ongoing obligation for a compliance audit to test. Where an engagement covers a historical period before that date, ESR compliance for those earlier financial years — including any outstanding notices or penalties — may still be relevant and is scoped in explicitly where that history matters.
Does a compliance audit review visa and GDRFA/ICP work-permit administration?
Where scoped to include workforce compliance beyond WPS payroll timing, yes — a compliance audit can test whether employee visa status and quota utilisation are being tracked and evidenced against GDRFA and ICP requirements, and whether renewals and cancellations are processed on schedule rather than left to lapse.
Does a compliance audit test Emiratisation obligations under MOHRE's Nafis programme?
Where relevant to the entity's size and sector, a compliance audit can test whether Emiratisation quota tracking and reporting through MOHRE's Nafis programme is being monitored and evidenced on schedule, in the same way WPS payroll timing is tested, rather than assuming compliance because a notification was filed once.
How does a compliance audit work for a UAE Central Bank-regulated entity such as an exchange house or finance company?
For entities regulated by the UAE Central Bank — exchange houses, finance companies, payment service providers — a compliance audit is scoped to test the Central Bank's own prudential and conduct rulebook obligations alongside the standard FTA, MOHRE, and AML/CFT obligations most UAE businesses carry. This is coordinated closely with the client's existing regulatory or compliance function to avoid duplicating specialist supervisory work already underway.
Does a compliance audit test related-party transactions and transfer pricing documentation?
Yes, where the entity is registered for Corporate Tax. We test whether related-party transactions are properly documented and priced on an arm's-length basis where the related-party rules under Federal Decree-Law No. 47 of 2022 apply, since inadequate related-party documentation is one of the more common gaps a Corporate Tax compliance audit line uncovers.
What happens if AML/CFT testing during a compliance audit surfaces something that looks like it needs a goAML suspicious transaction report?
We escalate this to management immediately rather than waiting for the final report, and recommend the client's designated Money Laundering Reporting Officer or AML/CFT advisor assess whether a suspicious transaction report through the goAML platform is required, given the reporting obligations DNFBPs carry under Cabinet Decision No. 10 of 2019.
How is a compliance audit different from a due diligence audit for M&A?
A due diligence audit is transaction-specific — commissioned by a buyer, investor, or lender to assess a target company's financial, tax, and compliance position ahead of a specific deal, typically with a compressed timeline tied to the transaction schedule. A compliance audit is not transaction-driven; it is an independent, standing check of whether an entity's ongoing regulatory obligations are being met, whether or not a deal is in progress. In practice, compliance audit findings often feed directly into a due diligence exercise when a transaction does arise.
Does a compliance audit review import VAT and customs-linked positions?
For mainland and free zone entities that import goods, a compliance audit can test whether import VAT positions, customs declarations, and any related reverse-charge treatment are being correctly applied and reconciled against the general ledger, since these are common areas where the documentation supporting a VAT position is weaker than the return itself suggests.
How often should a compliance audit be repeated?
There is no fixed statutory frequency. PNPC generally recommends a periodic cycle proportionate to the entity's risk profile — more frequent for DNFBPs and DIFC/ADGM regulated entities carrying ongoing AML/CFT or rulebook obligations, and less frequent for lower-risk mainland or free zone entities without a specific trigger. Many clients align the cycle with a licence renewal date or an annual governance calendar rather than running it purely reactively.
What access does PNPC need to customer due diligence files for an AML/CFT compliance audit?
We need read access to a sample of actual customer onboarding files — identification and verification records, risk rating documentation, and any periodic review evidence — rather than just the policy document describing what onboarding should involve. Without access to the underlying files, an AML/CFT compliance audit line becomes an unsupported opinion rather than tested assurance.
Can a compliance audit be run remotely, or does PNPC need to be on-site?
Much of a compliance audit — document and filing review, sample testing against records, and draft findings discussion — can be conducted remotely where the client can provide read-only system access or clean record extracts. Certain elements, such as observing physical document custody or the final report presentation to the board, are often more effective delivered in person, and the split is agreed explicitly at scoping stage.
Does PNPC issue a formal compliance certificate at the end of the engagement?
PNPC issues a findings report — an obligation-by-obligation assessment with evidence summary, risk ratings, and remediation recommendations — rather than a standalone compliance certificate. We will not issue a certificate of compliance that is not backed by the underlying evidence testing the findings report documents, since a certificate without testing would not represent genuine assurance.
What happens if a compliance audit finds a trade licence or free zone condition has lapsed?
We flag this as an urgent finding, since an expired or non-compliant licence condition can carry immediate operational consequences — restrictions on visa processing, banking relationships, or contract eligibility — beyond the financial exposure a tax or payroll gap typically carries. This is escalated to management the moment it is identified, not held for the final report.
How does a compliance audit handle a group spanning several UAE free zones plus a mainland entity?
We map obligations entity-by-entity across the group rather than applying a single obligation set uniformly, since each licensed entity's Corporate Tax treatment, VAT position, and licence-specific conditions can differ even within the same group. Intercompany transactions and related-party documentation consistency across the entities are tested as a distinct line item given their direct relevance to each entity's Corporate Tax position.
Is a compliance audit useful for a business that has only just registered for VAT or Corporate Tax?
Yes — arguably more useful early than after several filing cycles have already embedded a wrong approach. A compliance audit run after the first one or two filing cycles confirms the new registration's obligations are being correctly discharged from the outset, rather than only discovering an error once it has been repeated across several returns.
Does a compliance audit coordinate with a bank's own compliance or covenant review?
Where a bank facility includes compliance representations or covenant conditions, PNPC can scope a compliance audit specifically to test those named conditions, and — with management's consent — share relevant findings with the client's relationship bank ahead of a facility review or renewal, reducing the risk of a covenant breach surfacing unexpectedly.
Can a compliance audit be combined with an internal control over financial reporting (ICFR) review?
Yes, where useful. A compliance audit's obligation testing and an ICFR review's control-design and operating-effectiveness testing are complementary — many PNPC engagements scope both together for a client preparing for a listing, a significant financing round, or a first-time consolidated audit, since the underlying evidence (filed returns, reconciliations, approval records) overlaps substantially.
What if the finance team disagrees with a compliance audit finding?
We discuss draft findings with process owners before finalising the report, specifically to correct any factual errors and to reach an agreed, realistic remediation timeline. Where a genuine disagreement over the risk rating or interpretation remains, it is documented transparently in the final report rather than quietly softened or removed.
Does a compliance audit review contractual compliance obligations, not just regulatory ones?
Yes, where the entity has franchise, agency, distribution, or facility agreements containing specific compliance reporting duties to a principal, licensor, or lender, a compliance audit can test whether those contractual obligations are being met and evidenced, in addition to the statutory and regulatory obligations that form the core of most engagements.
What is the single biggest driver of compliance audit cost beyond the number of obligations tested?
Headcount and legal-entity count generally matter more than obligation count alone. A single entity with a small headcount and one or two obligation categories is a comparatively contained review; a multi-entity group with a larger workforce requires proportionally more payroll, visa, and — where DNFBP-relevant — customer due diligence files to be sampled, which drives fieldwork hours regardless of how many obligation categories are formally in scope.
How does compliance audit timeline differ between a single free zone entity and a mainland-plus-multiple-free-zone group?
A single free zone entity with organised records and one or two obligation categories can often be reviewed within a few weeks. A mainland-plus-multiple-free-zone group requires a separate obligation map for each licensed entity, cross-entity related-party testing, and typically a larger volume of filings and customer files, which extends the timeline materially — the exact figure is confirmed once the entity count and obligation categories are agreed at scoping.
Does an offshore company, such as a RAK ICC or JAFZA offshore entity, need a compliance audit?
An offshore company that holds no trading licence and does not conduct business inside the UAE typically carries a much narrower obligation set than a mainland or free zone trading entity — generally centred on registered agent, beneficial ownership, and annual return conditions rather than VAT, WPS, or a trading Corporate Tax profile. Where a compliance audit is commissioned for such a vehicle, PNPC scopes it to the obligations that genuinely attach to an offshore structure rather than padding it with obligations that do not apply.
What documentation specifically proves WPS compliance beyond the internal payroll register?
Beyond the payroll register itself, a compliance audit looks for the Salary Information File (SIF) confirmation from the paying bank or exchange house evidencing that the submitted file was actually accepted and processed, not merely generated internally, alongside the underlying salary transfer timing records. A payroll register alone does not prove WPS compliance — the bank-side confirmation is what closes the evidentiary loop.
What happens to a compliance audit finding if the entity's Corporate Tax registration status changes mid-review?
We update the obligation map to reflect the change and re-scope the affected testing lines accordingly, since a Corporate Tax registration change mid-review can affect which filing obligations, related-party rules, or Qualifying Free Zone Person conditions are actually in scope for the review period. This is communicated to management as a scope adjustment rather than silently absorbed into the original plan.
Can a compliance audit be repeated specifically to confirm nothing lapsed after a licence renewal?
Yes. A short, focused follow-up review after a licence renewal — confirming the renewed licence conditions, any updated activity codes, and continued VAT, Corporate Tax, and WPS compliance — is a common and proportionate use of a compliance audit, particularly where the renewal process itself introduced new conditions or activity restrictions.
Does a compliance audit review amendments to trade licence activity codes?
Yes, where an entity has amended its licensed activity codes, a compliance audit checks that the entity's actual operations remain within the amended scope and that any conditions attached to the new activity — additional approvals, sector-specific licences, or regulator notifications — have been correctly obtained and evidenced.
What happens to compliance audit findings if the entity later winds down or exits the UAE?
Where a wind-down or exit is planned, a final-cycle compliance audit run ahead of licence cancellation or a sale helps confirm all obligations are current so closure, deregistration, or completion is not delayed by an unresolved compliance gap. Findings from an earlier compliance audit cycle also inform what needs to be resolved before a clean exit can proceed.
How does a compliance audit engagement differ for a newly incorporated entity with less than one year of trading history?
For a very young entity, the obligation universe is often narrower simply because fewer filing cycles have occurred, but the review still tests whether the obligations that do apply — initial VAT or Corporate Tax registration timing, first WPS submissions, and initial licence conditions — were correctly discharged from day one, since early-stage errors are cheaper to correct before they compound across multiple filing cycles.
Does a compliance audit review foreign-currency-denominated contracts or FX exposure reporting?
Where relevant to the entity's activity, a compliance audit can review whether foreign-currency-denominated contracts are being accounted for and reported consistently, and whether any related VAT or Corporate Tax positions arising from foreign-currency transactions are correctly translated and documented — though FX risk management itself is a treasury advisory matter distinct from the compliance testing a compliance audit performs.
Is a compliance audit different for a holding company with no direct trading activity?
Yes — a pure holding company with no direct trading activity typically has a narrower obligation set (corporate and shareholding records, intercompany agreements, and any Corporate Tax related-party position on dividends or intercompany charges) than an operating trading entity, and a compliance audit for a holding company is scoped accordingly rather than testing VAT or WPS obligations that simply do not arise from its activity.
What happens if a compliance audit is commissioned midway through a Corporate Tax filing cycle?
We scope the review around the filing cycle's status — testing the completed portion of the cycle against the evidence available, and flagging any preparation gaps for the remaining filing period before the deadline arrives, rather than waiting until the cycle closes to identify an issue that could still be corrected in time.
Does PNPC test the specific timing gap between salary due date and WPS transfer date, or just whether a transfer happened at all?
We test the specific timing gap, not just whether a transfer eventually happened — MOHRE's WPS framework is concerned with wages being paid in the amount and at the time agreed in the employment contract, so a compliance audit reconciles the contractual due date against the actual WPS transfer date for a sample of pay periods, not merely whether a salary transfer record exists somewhere in the system.
How does a compliance audit treat a business that recently changed its free zone authority?
Where an entity has moved its licence from one free zone authority to another, a compliance audit tests whether the new authority's specific licence conditions, Qualifying Free Zone Person analysis (if relevant), and any registration continuity requirements have been correctly re-established under the new authority, rather than assuming the obligations carried over unchanged from the prior free zone.
Can a compliance audit be used to satisfy a franchisor's periodic compliance reporting requirement?
Yes, where a franchise or licensing agreement requires the UAE licensee to periodically demonstrate compliance with named conditions to the franchisor or licensor, a compliance audit can be scoped specifically around those contractual reporting terms, in addition to or alongside the statutory and regulatory obligations most engagements cover.
What is the typical output format of a PNPC compliance audit — a written report, a presentation, or both?
PNPC issues a written, obligation-by-obligation findings report as the primary deliverable, and — particularly where the engagement was commissioned by a board or audit committee — this is typically accompanied by a partner-led presentation summarising key findings, risk ratings, and the recommended management action plan.
Does PNPC benchmark compliance audit findings against industry peers?
A compliance audit is scoped to test whether the entity itself is meeting its own named obligations with evidence, rather than to benchmark its findings against peer companies — peer benchmarking is a different, comparative exercise that would require access to other companies' compliance data that is not available or appropriate to include in an individual client's engagement.
What if the entity has multiple trade licences under one legal entity across different emirates?
Where one legal entity holds multiple trade licences across different emirates or free zones, a compliance audit maps the licence-specific conditions for each licence separately, since renewal dates, activity scope, and any local approvals can differ by emirate even though the underlying legal entity and its tax registrations remain the same.
Does a compliance audit review dividend or profit repatriation compliance for cross-border shareholders?
Where relevant, a compliance audit can review whether dividend or profit distributions to overseas shareholders are documented consistently with the entity's corporate records and Corporate Tax position, though the shareholder's home-country tax treatment of the remittance itself — such as Indian withholding or reporting requirements on the recipient side — falls outside the UAE entity's compliance audit and is addressed separately with the relevant home-country advisor.
Are PNPC compliance audit reports issued in English, Arabic, or both?
PNPC issues compliance audit reports in English as standard, and can arrange an Arabic translation of the final report or specific sections where the client needs it for a regulator, board member, or third-party recipient who requires Arabic-language documentation — this is agreed at scoping stage rather than assumed by default.
Does a compliance audit for a DIFC entity review data protection compliance?
Where scoped to include it, a compliance audit for a DIFC-registered entity can test whether the entity's data-handling practices are consistent with its own documented data protection policies and any applicable DIFC data protection framework obligations relevant to its licence category — this is typically coordinated with the client's data protection or legal advisor given the specialist nature of data protection compliance.
What if the entity has never registered for VAT despite exceeding the mandatory threshold?
This is treated as an urgent finding rather than a routine one, since operating past the mandatory VAT registration threshold under Federal Decree-Law No. 8 of 2017 without registering carries direct exposure once identified. We escalate this to management and the client's tax advisor immediately so a corrective registration and any related voluntary disclosure can be actioned without delay, rather than surfacing it only in the final report.
Can PNPC's compliance audit satisfy a due diligence requirement from a prospective joint-venture partner rather than a pure acquirer?
Yes. A prospective JV partner's due diligence questions on tax, payroll, and AML/CFT compliance are frequently very similar to what a compliance audit already tests, and PNPC can scope a compliance audit specifically to produce a report suitable for sharing with a JV counterparty, subject to the client's own confidentiality terms and the counterparty's agreed reliance scope.
How does a compliance audit treat a penalty already assessed by the FTA or MOHRE before the review started?
An already-assessed penalty is documented as a known item with its payment or dispute status confirmed, and the review then tests whether the underlying process that caused the penalty has actually been corrected, since a paid penalty with no process fix in place typically means the same gap will recur in the next filing cycle.
How does India's statutory audit requirement compare to the UAE's approach when a compliance audit covers a cross-border group?
India's Companies Act generally mandates a statutory audit for companies regardless of size, whereas the UAE ties the external audit requirement to licence conditions imposed by the DED or the relevant free zone authority rather than a universal company-law mandate applying to every entity type. For a cross-border group, this means the Indian entity's statutory audit obligation is essentially automatic, while the UAE entity's audit and broader compliance obligations depend on its specific licence type and registrations — a distinction a compliance audit scoped across both jurisdictions accounts for explicitly rather than assuming parity.
PNPC compliance audit vs a typical generic provider
| Dimension | PNPC Global | Typical Generic Provider |
|---|---|---|
| Scope | Obligation map built from the entity's actual licence type, registrations, and sector | Fixed checklist applied regardless of what genuinely applies to the client |
| Evidence standard | Sample testing against filed returns, payroll records, and customer due diligence files | Confirmation that a policy document exists, without testing underlying evidence |
| Urgent findings | Escalated immediately, with a recommendation on voluntary disclosure where relevant | Held until the final report, delaying any corrective filing |
| Cross-border capability | Coordinated UAE-India compliance review for group structures under one engagement team | Separate, disconnected advisors in each jurisdiction with limited context-sharing |
| Regulatory currency | Findings grounded in current FTA, MOHRE, and DFSA/FSRA guidance, refreshed each cycle | Static templates that can lag behind current regulatory guidance |
| Remediation tracking | Agreed action plan tracked to completion, with follow-up testing where warranted | Report delivered with no structured follow-up on whether gaps were actually closed |
| Team continuity | Partner-led scoping and reporting, with senior team members on fieldwork | Engagement frequently delegated to junior staff with limited partner oversight |
| Free zone / mainland nuance | Obligations mapped entity-by-entity, recognising Qualifying Free Zone Person and mainland VAT/customs distinctions | Same generic obligation set applied across mainland and free zone entities regardless of licence type |
| Workforce & Emiratisation testing | GDRFA/ICP visa administration and MOHRE Nafis Emiratisation tracking tested alongside WPS, where relevant | Workforce compliance narrowed to WPS payroll timing alone, missing visa and Emiratisation exposure |
| Central Bank / regulated-entity experience | Compliance audits for exchange houses, finance companies, and payment service providers scoped to the Central Bank's own rulebook obligations | Generalist scope that does not account for sector-specific prudential or conduct requirements |
- 01
Obligation mapping specific to the entity's licence type, tax registrations, DNFBP status, and regulator category
- 02
Risk-ranked scoping so the highest-exposure obligations are tested first
- 03
VAT filing accuracy testing against Federal Decree-Law No. 8 of 2017 and current FTA guidance via EmaraTax records
- 04
Corporate Tax position review under Federal Decree-Law No. 47 of 2022, including related-party documentation and Qualifying Free Zone Person evidence where claimed
- 05
WPS payroll compliance reconciliation against MOHRE requirements, including bank-side SIF acceptance confirmation, not just the internal payroll register
- 06
AML/CFT programme testing for DNFBPs, including sampled customer due diligence file review and goAML registration confirmation
- 07
DFSA/FSRA rulebook obligation testing for DIFC/ADGM regulated entities, scoped to the specific licence category
- 08
Sample-based evidence testing, not policy-existence confirmation alone, with a documented and defensible sampling methodology
- 09
Immediate escalation of any gap serious enough to warrant urgent corrective action or voluntary disclosure
- 10
Interim findings briefing partway through fieldwork, so urgent items don't wait for the final report
- 11
Obligation-by-obligation findings report with risk ratings and named remediation owners
- 12
Draft report circulated to process owners for factual-accuracy review before risk ratings are finalised
- 13
Board or audit committee presentation where the engagement was board-commissioned
- 14
Coordination with the client's existing tax advisor or statutory auditor, with management's consent
- 15
Cross-border UAE-India compliance review capability for group structures
- 16
Agreed management action plan with committed remediation dates
- 17
Confidentiality and report-distribution terms agreed explicitly, including any third-party reliance scope
- 18
Follow-up testing of previously flagged obligations where warranted
- 19
Post-engagement advisory availability for a defined period to answer follow-up questions on the findings
- 20
Engagement workpapers and evidence archived to support future re-testing or a later regulator query
Talk to a PNPC partner about scoping a compliance audit around the obligations that genuinely apply to your UAE entity — before a regulator, lender, or auditor finds the gap first.
Jurisdiction
Free zone, mainland & offshore
Ready to get started?
Tell us about your requirement — a UAE specialist responds within 24 hours.