Insights · Vendor management

IT vendor and outsourcing management for DFSA and FSRA firms

How to manage IT providers when you are regulated in DIFC or ADGM: a register, tiering, due diligence, contract terms and ongoing oversight.
The short answer

Regulators treat your IT providers as part of your control environment. In DIFC, GEN 5.3.21 says outsourcing does not relieve you of responsibility and expects due diligence and supervision. In ADGM, the FSRA cyber rules in force since 31 January 2026 set explicit expectations for due diligence, contract terms and oversight of ICT providers. Keep a register, tier your vendors and contract for the controls you need.

Key points
  • You stay responsible for outsourced IT. Due diligence before, supervision during and an exit plan after.
  • Keep a register of providers and tier them by criticality; material arrangements get the closest scrutiny.
  • Contracts should cover security obligations, review and audit rights, incident notification, subcontractors and data return.
  • Your MSP is itself a critical vendor. Assess it like one.

Why vendor management is now an IT topic

A modern firm runs on providers: cloud platforms, email, managed IT, security tooling, payment and market-data services. When one fails or is breached, your regulator will ask what you did to choose it, contract with it and watch it. Both the DFSA and the FSRA now put that question in the cyber rules as well as the outsourcing rules.

Build a register and tier it

List every provider that touches firm data or supports a critical process, including cloud services staff adopted informally. Record what it does, what data it holds, where it runs, who owns the relationship and when it was last reviewed. Then tier them:

  • Critical or material. The DFSA’s guidance describes material outsourcing as a service whose weakness or failure would cast serious doubt on your continuing ability to remain fit and proper or to comply with DFSA-administered laws and rules.
  • Important. Failure would disrupt normal operations or expose client data, but you could cope for a while.
  • Standard. Low impact, low data sensitivity.

Due diligence before you sign

Scale the checks to the tier. For a critical provider, look for:

  • Independent assurance: an ISO 27001 certificate with a relevant scope, or an independent audit report, that you have actually read.
  • Security controls that match your requirements, and a way to verify them.
  • Where data is stored and processed, and which subcontractors are involved.
  • Incident history, breach notification practice and business continuity arrangements.
  • Financial stability, insurance and how the provider vets and supervises its own staff.
  • How you would leave: data return, transition help and the time it would take.

What the contract should say

The FSRA’s rules for ADGM firms are explicit, and they are a good template even if you are in DIFC. Contracts with ICT providers should include:

  • Security obligations that match the standards you verified during due diligence, so you have recourse if the provider falls short.
  • Review and audit rights. You can audit, review the provider’s control environment or accept independent audit reports, with frequency and depth proportionate to the criticality of the service and the sensitivity of the data.
  • Incident notification and cooperation. The provider must tell you about cyber incidents with a material impact, and help with remediation.
  • Subcontracting controls. Disclosure of current arrangements, notice of changes, a right to object and termination options if concerns are not resolved.
  • Data return or destruction when the contract ends.

Add the practical terms too: service levels, support hours, notice periods and transition assistance on exit.

Ongoing oversight

  • Review each provider on a schedule based on its tier, and record the outcome.
  • Collect assurance reports and certificates each year and check scope and dates.
  • Track service performance and incidents against the contract.
  • Require notice of material changes, such as new subcontractors or data locations.
  • Test your exit plan for critical providers, on paper at least.

Your MSP is a critical vendor

A managed service provider usually holds privileged access to your systems, which makes it one of your most important providers. Ask it what it would ask of anyone else: its certificates and their scope, how it vets and supervises engineers, how it controls and logs privileged access, how it handles incidents and how quickly it will tell you about one. At Cre8 IT we expect these questions, and we can supply the evidence as part of onboarding.

Sources and further reading

Last reviewed 19 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.

Written by
CEO, Cre8 IT
Rob Crossley is CEO of Cre8 IT, a Dubai-born managed IT and cyber security company that has supported businesses across the UAE, Saudi Arabia and the UK since 2012. Cre8 IT is certified to ISO 27001:2022 and ISO 9001 and is a certified Microsoft Partner.
FAQ

Frequently asked questions

Is our managed IT provider a “material” outsourcing?

It often is. The DFSA’s test asks whether weakness or failure of the service would cast serious doubt on your continuing ability to remain fit and proper or to comply with DFSA-administered laws and rules. Assess this yourself, record the reasoning and revisit it when the arrangement changes.

Do we need a right to audit in every IT contract?

The FSRA’s rules for ADGM firms expect contracts to allow you to verify that a provider meets its security obligations. That can be your own audit, a review of the provider’s control environment or independent audit reports, depending on how critical the service and how sensitive the data. On-site audits are not always needed.

How often should we review our providers?

Match the frequency to risk. Critical providers deserve at least an annual review, including assurance reports and performance. Lower tiers can be reviewed less often, provided you still notice material changes.
Related guides

Keep reading

Each guide links to the regulator’s own text and shows when it was last reviewed.
DFSA and DIFC

DFSA cyber and IT requirements: what DIFC firms need to evidence

A plain-English guide to the DFSA’s cyber risk management rules (GEN 5.5), its outsourcing expectations (GEN 5.3.21) and the evidence a DIFC firm should be able to show.
6 min read · Reviewed 19 September 2026
ISO 27001

ISO 27001 for financial firms: how it supports DFSA and FSRA expectations

What ISO/IEC 27001:2022 certifies, how its controls map to DFSA and FSRA cyber expectations, and how to read a supplier’s certificate.
4 min read · Reviewed 19 September 2026
Audit readiness

IT audit readiness for DIFC and ADGM firms: an evidence-first checklist

How to be ready when a regulator, auditor or client asks for proof of your IT and security controls: the evidence pack, a mock audit and a six-week plan.
3 min read · Reviewed 19 September 2026

Talk to a specialist about your obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.