In the UAE, corporate governance for listed companies is not a matter of best-practice aspiration. It is codified. The Securities and Commodities Authority (SCA) sets the rules through its Joint Stock Companies Governance Guide — Chairman of SCA Board Decision No. (3/Chairman) of 2020 — and has tightened them since, with amendments taking effect in February 2022 and a 2024 update that put fresh weight on the demonstrable effectiveness of internal controls, governance, and risk management.

For internal audit, three requirements sit at the centre of that framework.

1. An independent audit committee is mandatory

Every public joint-stock company listed on the Dubai Financial Market or Abu Dhabi Securities Exchange must establish an audit committee. It is not optional, and getting it wrong is visible: a company without a compliant committee has to disclose the non-compliance in its annual corporate governance report to the SCA, which can respond with a warning, a fine, or — for persistent failures — suspension of trading.

The composition rules exist to protect objectivity:

2. Internal audit answers to the committee, not management

Under the code, internal audit is an objective assurance and advisory function that evaluates risk management, internal control, and governance — and reports functionally to the audit committee. That reporting line is the mechanism that keeps assurance independent of the executives being assured. The committee approves the internal audit policy, reviews internal audit reports, and owns the response when risk-management weaknesses surface.

3. The bar is higher for banks

Listed companies follow the SCA. Banks answer to the Central Bank of the UAE (CBUAE), whose rulebook is more prescriptive again. Across the GCC, the same shape recurs, with local variations:

Requirement UAE — SCA (listed JSCs) UAE — CBUAE (banks) Saudi — CMA (listed)
Audit committee Mandatory Mandatory Mandatory
Composition ≥3, primarily independent non-executive Independent / non-executive; chair independent 3–5, no executives, majority independent
Internal audit reporting line Functionally to the audit committee To the Board / Board audit committee Supervised by the audit committee
Financial expertise Recommended Collective audit & finance experience At least one finance / accounting specialist

For banks, the CBUAE also requires a permanent, independent internal audit function with a risk-based annual plan approved by the board audit committee, full access to records, and a head of internal audit with at least five years of banking-audit experience — all inside a formal three-lines-of-defence model.

What this means for the function

The common thread across the UAE rules is a shift from asserting governance to evidencing it. A committee that has to show its internal controls are effective needs an internal audit function that can produce that evidence on demand: a documented risk-based plan, working papers with a clean review trail, findings tracked to a verified close, and a board-ready view that is the system's own record rather than a slide rebuilt each quarter.

That is difficult to sustain in spreadsheets and email, and straightforward in a platform built around the audit lifecycle. It is the reason functions across the region are moving to systems like ControlVista, where the assurance the regulator asks for is produced by the work rather than assembled after it.

Sources

Building a UAE-ready internal audit function? See the platform or request a demo.