For owners, boards and finance leads of Dubai companies that have grown past the point where the founder sees every transaction, and need someone independent of the finance team to check that controls are working.
DirhamWise runs outsourced and co-sourced internal audit: we build a risk-based audit plan, test your controls and processes, assess fraud risk, and report findings to the board or owners with agreed actions that we follow up until they are closed.

Internal audit is an independent review of how your business is run: whether risks are identified, whether controls work as designed, and whether management information can be trusted. It is commissioned by the owners, board or audit committee, and the scope is theirs to set. That makes it different from a statutory external audit, which gives an opinion on the annual financial statements for shareholders, banks and authorities. If you want the full comparison, read our guide to internal audit vs external audit.

Our engagements cover five areas:
We frame control testing on the COSO Internal Control – Integrated Framework (2013), which looks at five components: control environment, risk assessment, control activities, information and communication, and monitoring. Our planning, fieldwork and reporting approach draws on the Institute of Internal Auditors’ Global Internal Audit Standards, which took effect on 9 January 2025. Using recognised frameworks means your board, investors and external auditor can follow how we reached each conclusion.
An audit plan that tests everything equally wastes money. We start from the risks that could cost you most and work back to the processes and controls that should prevent them.
| Stage | What we do | What you receive |
|---|---|---|
| 1. Understand the business | Interviews with owners and department heads; review of the organisation chart, delegation of authority, ERP or accounting system and recent management accounts | A short business and process map |
| 2. Build the audit universe | List every auditable area: finance cycles, operations, IT, HR, tax compliance, branches and group entities | Audit universe register |
| 3. Rate the risks | Score each area for likelihood and impact, taking account of transaction volumes, cash handling, manual steps, past errors and recent changes | Risk register and heat map |
| 4. Agree the plan | Prioritise high-risk areas, set timing around your year-end and busy periods, and agree days per review | Annual (or rolling) internal audit plan |
| 5. Set the mandate | Draft an internal audit charter covering purpose, authority, access to records, reporting lines and independence | Charter for board or owner approval |
The plan is not fixed. We revisit the risk ratings when something changes: a new branch, a new ERP, a large contract, a change of finance manager, or new tax rules such as those described below.
For each review we document how the process works, identify the key controls, then test a sample of transactions to see whether those controls operated. A control that exists on paper but is skipped in practice is reported as a gap.
| Process area | Controls we test | Typical findings in owner-managed businesses |
|---|---|---|
| Cash and bank | Bank reconciliations, dual authorisation of payments, petty cash counts, access to online banking | Reconciliations prepared late or not reviewed; one person able to create and approve a payment |
| Procure-to-pay | Vendor onboarding and supplier verification records, purchase orders, three-way match, approval limits | Vendors added without checks; invoices paid without a purchase order or goods receipt |
| Order-to-cash | Credit approval, pricing and discounts, invoicing, collections, credit notes | Discounts given outside policy; credit notes raised without approval |
| Inventory | Stock counts, write-offs, goods received, slow-moving stock review | Book stock differing from physical counts; write-offs not approved |
| Payroll and HR | Joiner and leaver processing, salary changes, overtime approval, end-of-service calculations | Leavers paid after exit; salary changes without documented approval |
| Fixed assets | Asset register, tagging, disposals, capital approval | Register not matching assets on site; disposals not recorded |
| IT and system access | User rights in the accounting system or ERP, password rules, backups, audit trail | Shared logins; finance staff able to post and approve their own entries |
Vendor onboarding now carries a tax consequence as well as a fraud one. From 1 October 2026 the FTA expects documented supplier checks before input VAT is deducted, so a weak onboarding process can cost recoverable VAT as well as cash. We test both sides in the same review; the rules are set out in the tax-controls section below.
Where written procedures are missing or out of date, we map the actual process and recommend a practical control set that suits your headcount. Small finance teams cannot always separate every duty, so we suggest compensating controls such as owner review of the bank statement or monthly exception reports. If the underlying bookkeeping needs rebuilding first, our outsourced accounting team can do that under a separate engagement.
Many control failures in UAE companies show up first as a tax problem: a missing invoice, a record that cannot be produced, an input VAT claim on a supplier nobody checked, or an error found too late. We add a tax-controls review to the plan so these are picked up internally, before an FTA audit.
| Area | The rule | What we check |
|---|---|---|
| Corporate tax records | Records must be kept for 7 years after the end of the tax period they relate to (Federal Decree-Law 47/2022, Art. 56) | Retention policy, where records are stored, and whether older periods can actually be retrieved |
| VAT and tax procedures records | Failure to keep required records carries a penalty of AED 10,000, or AED 20,000 for a repeat within 24 months of the last violation (Cabinet Decision 40/2017 as amended by Cabinet Decision 129/2025, in force since 14 April 2026) | Completeness of the VAT audit trail from invoice to return |
| Tax invoices and credit notes | Failure to issue a tax invoice or tax credit note within the legal period: AED 2,500 for each case detected (same decision) | Sample of sales invoices and credit notes against VAT requirements |
| Supplier and supply verification | From 1 October 2026, FTA Decision 13/2026 requires a business to verify a supplier’s identity, place of business and risk indicators before deducting input VAT, to review each supply’s price, payment terms and commercial logic, and to keep a documented policy naming who runs and supervises these checks. Suppliers are verified on first dealing and again if not verified in the previous 12 months | Whether vendor onboarding captures the required evidence, whether re-verification is scheduled, and whether the written policy exists and is followed |
| Bank confirmation for larger suppliers | Under the same decision, where supplies from one supplier exceed AED 375,000 over the previous 12 months (or are expected to over the next 12), a written confirmation from a UAE bank that the supplier holds an account is required. Supplies under AED 10,000 excluding VAT are exempt, unless that supplier’s total exceeds AED 100,000 over 12 months | Which suppliers cross the thresholds and whether bank confirmations are on file |
| Cash payments and input VAT | Cabinet Decision 149/2026 adds Article 54(3) to the VAT Executive Regulation from 1 October 2026: input VAT cannot be recovered on a supply above an amount set by Ministerial decision where it is paid, or intended to be paid, in cash | How cash payments to suppliers are approved and recorded, so claims can be tested against the Ministerial limit when it applies |
| Correcting errors | From 1 April 2026, a tax difference above AED 10,000 needs a voluntary disclosure within 20 business days; AED 10,000 or less can be corrected in the next return (Cabinet Decision 17/2026) | Whether your team has a routine to spot, quantify and escalate errors in time |
| E-invoicing readiness | Businesses with revenue of AED 50 million or more must appoint an Accredited Service Provider by 30 October 2026 and go live by 1 January 2027; those below AED 50 million by 31 March 2027 and 1 July 2027 (Ministerial Decision 244/2025 as amended by Ministerial Decision 66/2026) | Master data quality, invoice approval flow and project ownership |
| Beneficial ownership | Changes to the beneficial owner register must be recorded within 15 days of becoming aware of them (Cabinet Decision 109/2023, Art. 8) | Whether the register matches the current shareholding and control |
Controls also matter for the external audit. Under Ministerial Decision 84/2025, for tax periods starting on or after 1 January 2025, audited financial statements are required for corporate tax purposes where revenue exceeds AED 50 million, for every Qualifying Free Zone Person, and for every tax group. A business whose controls work tends to have a smoother year-end audit with fewer adjustments. For filing and advisory work, see our VAT services, corporate tax services and e-invoicing pages; if an error has already been found, our voluntary disclosure team can help.
Most internal fraud in smaller companies relies on the same weaknesses: one person controlling a whole process, owners too busy to review, and nobody looking at the data. Our fraud-risk assessment looks at where opportunity exists and tests for signs that it has been used.
If testing turns up indicators of actual fraud, we report them promptly to the person named in the charter, normally the chair of the board or the owner, and advise on next steps such as preserving evidence and bringing in specialist investigators or legal counsel. Where money-laundering risk is part of the picture, our AML compliance service covers the regulatory side.

Internal audit only helps if findings lead to action. Each review ends with a draft report discussed with the process owner, then a final report to whoever the charter names: the board, an audit committee, or the owners in a family business.
Every report contains:
| Rating | Meaning | Expected response |
|---|---|---|
| High | A control is missing or failing, with a real risk of loss, misstatement, tax penalty or fraud | Immediate action, reported to the board or owners |
| Medium | A control exists but is inconsistent or poorly designed | Fixed within an agreed timescale |
| Low | An improvement to efficiency or documentation | Addressed in the normal course of business |
We keep an action tracker across all reviews and retest closed findings, so the board sees what has actually been fixed rather than what has been promised. Periodic summaries show open actions by age and risk rating, and any themes that repeat across departments.
There are three ways to set up the function. The right one depends on your size, how complex your operations are, and whether you already have internal audit staff.
| Model | Outsourced | Co-sourced | In-house team |
|---|---|---|---|
| Who does the work | DirhamWise delivers the full plan | Your internal auditor plus DirhamWise for set reviews or extra capacity | Your own employees |
| Cost basis | Fixed fee per review or per year | Fixed fee for the reviews we cover | Salaries, visas, training and benefits all year |
| Skills available | A team covering finance, tax, payroll and IT controls | Specialist skills added where your team has gaps | Limited to the people hired |
| Independence from management | External by design | Strengthened by an external reviewer | Depends on reporting line |
| Best suited to | SMEs and family groups with no internal audit function | Companies with one or two internal auditors | Larger groups with continuous audit needs |
Many companies start outsourced, move to co-sourcing once they hire a head of internal audit, and keep external support for specialist areas such as tax controls or IT access. If you also need wider finance leadership, our CFO services can sit alongside internal audit, though never on the same area we are auditing.
Internal auditors must be free to report problems, including problems created by management. We keep that independence in three ways:
A typical first engagement runs like this:
Fees are fixed per engagement and depend on the number of entities, locations, processes in scope and how often you want reviews. Businesses usually start with either a one-off control review or a rolling annual plan. Contact us for an internal audit quote; our monthly accounting packages are listed separately on the pricing page. Our team is based at ParkLane Tower, Business Bay, and works Monday to Saturday, 9:00am to 6:00pm.
Internal audit gives owners and the board an independent view of whether risks are managed, controls work and financial information is reliable. It finds weaknesses before they become losses, fraud, tax penalties or audit qualifications, and it tracks whether management fixes them.
Functionally, internal audit should report to the board, an audit committee or, in owner-managed companies, the owners. Day-to-day administration can sit with the CEO or managing director, but the auditor must be able to raise findings directly with those charged with governance. The reporting line is set out in the internal audit charter.
A charter is a short document approved by the board or owners that defines internal audit’s purpose, authority, scope, reporting lines, independence and access to people, records and systems. We draft it during planning so everyone knows what internal audit can see and whom it reports to.
We assess risks, agree a plan, then for each area document the process, identify key controls, test a sample of transactions or the full data set, discuss findings with the process owner, issue a report with agreed actions, and retest once those actions are complete.
Internal audit reviews risks and controls for management and the board, with a scope they choose. External audit gives an independent opinion on the annual financial statements. Our internal vs external audit guide explains the difference in detail, and our audit and assurance page covers statutory audits.
High-risk areas such as cash, procurement and payroll are usually reviewed every year, and lower-risk areas every two or three years. The risk assessment sets the cycle, and it is reviewed when the business changes, for example after an acquisition, a system change or new tax rules.
International auditing standards allow external auditors to evaluate internal audit work and, where they judge it appropriate, take it into account in their own audit. The decision is theirs. Clear documentation, sound methodology and independence make that more likely.
Tell us about your business, your systems and the areas that worry you. We will propose a risk-based scope and a fixed fee.
+971 56 500 6694 · info@dirhamwise.com · Contact form
ParkLane Tower, Park Regis, Business Bay, Dubai · Monday to Saturday, 9:00am to 6:00pm