Insights · Audit readiness

IT audit readiness for DIFC and ADGM firms: an evidence-first checklist

How to be ready when a regulator, auditor or client asks for proof of your IT and security controls: the evidence pack, a mock audit and a six-week plan.
The short answer

Audit readiness means you can produce, on request, evidence that your IT and security controls exist, operate and are reviewed. Build a small standing evidence pack, give each item an owner and a review date, and test it with a mock audit before a regulator, auditor or client does it for you.

Key points
  • Policies say what you intend, procedures say how, and records prove it happened. Auditors ask for all three.
  • Keep a standing evidence pack with an owner and a review date for each item.
  • Run a mock audit: pick five controls and time how long it takes to produce the proof.
  • Ask your MSP for regular reports that double as evidence.

Who is likely to ask

  • Your regulator, through a supervisory visit, a thematic review or an ad hoc request.
  • External auditors and certification bodies (for example for ISO 27001 or Cyber Essentials).
  • Clients, through due diligence questionnaires and security reviews.
  • Insurers and parent groups.

The questions are similar each time, which is the good news: one well-kept evidence pack answers most of them.

Policy, procedure and record

Auditors test three layers. The policy says what you intend (“all administrators use multi-factor authentication”). The procedure says how it is done. The record proves it happened (a report showing MFA coverage, dated last month). Firms usually have the first layer and are missing the third.

The evidence pack

Control areaEvidenceHow often
Asset managementHardware and software register, cloud service listReviewed quarterly
Access controlJoiner, mover and leaver tickets; access review sign-offs; admin role listReviews quarterly
AuthenticationMFA coverage report and list of exceptions with reasonsMonthly
PatchingPatch compliance report for devices and serversMonthly
Backup and recoveryBackup success reports and a restore test recordBackups daily; restore test at least quarterly
TestingPenetration test report and remediation trackerAnnually and after major change
Incident responseResponse plan, exercise record, incident logPlan reviewed and tested annually
AwarenessTraining completion records and phishing exercise resultsAnnually, with refreshers
Third partiesProvider register, due diligence files, review notesReviewed by risk tier
GovernanceMinutes showing the governing body or committee reviewed cyber riskAt least annually
Change managementChange records with approvalsOngoing

Run a mock audit

Pick five controls at random and ask the owner to produce the evidence within a day. Record how long each took, what was missing and who fixed it. Repeat annually and after any major change. The exercise usually finds problems no checklist does, such as evidence that exists only in one person’s inbox.

Common failure patterns

  • Policies with no records to show they are followed.
  • Evidence spread across mailboxes and shared drives.
  • Controls that exist, but only since last month, so there is no history.
  • No named owner, so nobody refreshes the evidence.
  • Scope drift: a new SaaS tool or office was never added to the register.

A six-week plan

  1. Week 1. Agree scope and owners. List the controls your regulator, clients and any certification will test.
  2. Week 2. Create the evidence folder structure and the asset and provider registers.
  3. Week 3. Set up regular reports (MFA, patching, backup, access) so evidence builds itself.
  4. Week 4. Run the first access review and record the sign-off. Test a restore.
  5. Week 5. Exercise the incident response plan with a short tabletop scenario.
  6. Week 6. Run a mock audit, log the gaps and assign fixes with dates.

What to ask your MSP for

A good managed service provider can supply much of this as a by-product of running your IT: monthly patch, backup, MFA and ticket reports, access review data, and change records. Make that a term of the service agreement, not a favour. Our vendor management guide covers what to put in the contract.

Sources and further reading

Last reviewed 19 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.

Written by
CEO, Cre8 IT
Rob Crossley is CEO of Cre8 IT, a Dubai-born managed IT and cyber security company that has supported businesses across the UAE, Saudi Arabia and the UK since 2012. Cre8 IT is certified to ISO 27001:2022 and ISO 9001 and is a certified Microsoft Partner.
FAQ

Frequently asked questions

How far back should our evidence go?

At least the period an audit or review covers, and in line with your firm’s record-keeping policy and any rules that apply to you. Regular, dated reports are far more convincing than evidence assembled at the last minute.

Who owns audit readiness: IT or compliance?

Both contribute, but accountability sits with senior management. The DFSA’s cyber rules, for example, make the governing body and senior management accountable for oversight of cyber risk. IT produces the technical evidence and compliance checks that it is complete.

How often should we run a mock audit?

At least once a year, and after any major change such as a new system, a new provider, an office move or an acquisition.
Related guides

Keep reading

Each guide links to the regulator’s own text and shows when it was last reviewed.
DFSA and DIFC

DFSA cyber and IT requirements: what DIFC firms need to evidence

A plain-English guide to the DFSA’s cyber risk management rules (GEN 5.5), its outsourcing expectations (GEN 5.3.21) and the evidence a DIFC firm should be able to show.
6 min read · Reviewed 19 September 2026
ISO 27001

ISO 27001 for financial firms: how it supports DFSA and FSRA expectations

What ISO/IEC 27001:2022 certifies, how its controls map to DFSA and FSRA cyber expectations, and how to read a supplier’s certificate.
4 min read · Reviewed 19 September 2026
Microsoft 365

Microsoft 365 governance for regulated firms: a practical baseline

How to govern Microsoft 365 in a DFSA- or FSRA-regulated firm: identity, devices, data, logging and licences, with a 30-day order of work.
4 min read · Reviewed 19 September 2026

Talk to a specialist about your obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.