The short answerRegulators treat your IT providers as part of your control environment. In DIFC, GEN 5.3.21 says outsourcing does not relieve you of responsibility and expects due diligence and supervision. In ADGM, the FSRA cyber rules in force since 31 January 2026 set explicit expectations for due diligence, contract terms and oversight of ICT providers. Keep a register, tier your vendors and contract for the controls you need.
Key points- You stay responsible for outsourced IT. Due diligence before, supervision during and an exit plan after.
- Keep a register of providers and tier them by criticality; material arrangements get the closest scrutiny.
- Contracts should cover security obligations, review and audit rights, incident notification, subcontractors and data return.
- Your MSP is itself a critical vendor. Assess it like one.
Why vendor management is now an IT topic
A modern firm runs on providers: cloud platforms, email, managed IT, security tooling, payment and market-data services. When one fails or is breached, your regulator will ask what you did to choose it, contract with it and watch it. Both the DFSA and the FSRA now put that question in the cyber rules as well as the outsourcing rules.
Build a register and tier it
List every provider that touches firm data or supports a critical process, including cloud services staff adopted informally. Record what it does, what data it holds, where it runs, who owns the relationship and when it was last reviewed. Then tier them:
- Critical or material. The DFSA’s guidance describes material outsourcing as a service whose weakness or failure would cast serious doubt on your continuing ability to remain fit and proper or to comply with DFSA-administered laws and rules.
- Important. Failure would disrupt normal operations or expose client data, but you could cope for a while.
- Standard. Low impact, low data sensitivity.
Due diligence before you sign
Scale the checks to the tier. For a critical provider, look for:
- Independent assurance: an ISO 27001 certificate with a relevant scope, or an independent audit report, that you have actually read.
- Security controls that match your requirements, and a way to verify them.
- Where data is stored and processed, and which subcontractors are involved.
- Incident history, breach notification practice and business continuity arrangements.
- Financial stability, insurance and how the provider vets and supervises its own staff.
- How you would leave: data return, transition help and the time it would take.
What the contract should say
The FSRA’s rules for ADGM firms are explicit, and they are a good template even if you are in DIFC. Contracts with ICT providers should include:
- Security obligations that match the standards you verified during due diligence, so you have recourse if the provider falls short.
- Review and audit rights. You can audit, review the provider’s control environment or accept independent audit reports, with frequency and depth proportionate to the criticality of the service and the sensitivity of the data.
- Incident notification and cooperation. The provider must tell you about cyber incidents with a material impact, and help with remediation.
- Subcontracting controls. Disclosure of current arrangements, notice of changes, a right to object and termination options if concerns are not resolved.
- Data return or destruction when the contract ends.
Add the practical terms too: service levels, support hours, notice periods and transition assistance on exit.
Ongoing oversight
- Review each provider on a schedule based on its tier, and record the outcome.
- Collect assurance reports and certificates each year and check scope and dates.
- Track service performance and incidents against the contract.
- Require notice of material changes, such as new subcontractors or data locations.
- Test your exit plan for critical providers, on paper at least.
Your MSP is a critical vendor
A managed service provider usually holds privileged access to your systems, which makes it one of your most important providers. Ask it what it would ask of anyone else: its certificates and their scope, how it vets and supervises engineers, how it controls and logs privileged access, how it handles incidents and how quickly it will tell you about one. At Cre8 IT we expect these questions, and we can supply the evidence as part of onboarding.
Sources and further reading
Last reviewed 19 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.
CEO, Cre8 IT
Rob Crossley is CEO of Cre8 IT, a Dubai-born managed IT and cyber security company that has supported businesses across the UAE, Saudi Arabia and the UK since 2012. Cre8 IT is certified to ISO 27001:2022 and ISO 9001 and is a certified Microsoft Partner.