Internal Audit Services in Dubai

INTERNAL AUDIT SERVICES

Independent checks that your controls actually work

For owners, boards and finance leads of Dubai companies that have grown past the point where the founder sees every transaction, and need someone independent of the finance team to check that controls are working.

DirhamWise runs outsourced and co-sourced internal audit: we build a risk-based audit plan, test your controls and processes, assess fraud risk, and report findings to the board or owners with agreed actions that we follow up until they are closed.

Analyst in a blazer and glasses reading a printed report beside her desk and laptop
INTERNAL AUDIT SERVICES

What's included

Risk-based annual audit plan
We map your processes, rank risks by likelihood and impact, and agree an audit plan that puts effort where losses are most likely.
Internal control reviews
Walkthroughs and sample testing of cash, procurement, sales, inventory, payroll and IT access controls, with gaps rated by risk.
Process audits and SOPs
We compare how work is actually done with your written procedures and help rewrite SOPs where they no longer match.
Fraud-risk assessment
Data tests for duplicate payments, split purchases, unusual journals and vendor-employee matches, plus a review of anti-fraud controls.
VAT and corporate tax controls
Checks on record retention, tax invoices, supplier verification before input VAT claims, and routines for correcting errors on time.
Board and management reporting
Clear reports with risk ratings, owners and dates, an action tracker, and follow-up testing until each finding is closed.

What our internal audit service covers

Internal audit is an independent review of how your business is run: whether risks are identified, whether controls work as designed, and whether management information can be trusted. It is commissioned by the owners, board or audit committee, and the scope is theirs to set. That makes it different from a statutory external audit, which gives an opinion on the annual financial statements for shareholders, banks and authorities. If you want the full comparison, read our guide to internal audit vs external audit.

Two people at a table going through printed forms line by line, with a pen, phone and tablet beside them

Our engagements cover five areas:

  • Risk assessment and audit planning – an audit universe for your business and a plan ranked by risk.
  • Internal control reviews – testing whether key controls exist, are designed properly and operate consistently.
  • Process audits – end-to-end reviews of procure-to-pay, order-to-cash, inventory, payroll and similar cycles.
  • Fraud-risk assessment – identifying where fraud could happen and testing the data for warning signs.
  • Reporting and follow-up – written findings for the board or owners, and tracking of management actions to closure.

We frame control testing on the COSO Internal Control – Integrated Framework (2013), which looks at five components: control environment, risk assessment, control activities, information and communication, and monitoring. Our planning, fieldwork and reporting approach draws on the Institute of Internal Auditors’ Global Internal Audit Standards, which took effect on 9 January 2025. Using recognised frameworks means your board, investors and external auditor can follow how we reached each conclusion.

How we build a risk-based internal audit plan

An audit plan that tests everything equally wastes money. We start from the risks that could cost you most and work back to the processes and controls that should prevent them.

Stage What we do What you receive
1. Understand the business Interviews with owners and department heads; review of the organisation chart, delegation of authority, ERP or accounting system and recent management accounts A short business and process map
2. Build the audit universe List every auditable area: finance cycles, operations, IT, HR, tax compliance, branches and group entities Audit universe register
3. Rate the risks Score each area for likelihood and impact, taking account of transaction volumes, cash handling, manual steps, past errors and recent changes Risk register and heat map
4. Agree the plan Prioritise high-risk areas, set timing around your year-end and busy periods, and agree days per review Annual (or rolling) internal audit plan
5. Set the mandate Draft an internal audit charter covering purpose, authority, access to records, reporting lines and independence Charter for board or owner approval

The plan is not fixed. We revisit the risk ratings when something changes: a new branch, a new ERP, a large contract, a change of finance manager, or new tax rules such as those described below.

Internal control reviews and process audits

For each review we document how the process works, identify the key controls, then test a sample of transactions to see whether those controls operated. A control that exists on paper but is skipped in practice is reported as a gap.

Process area Controls we test Typical findings in owner-managed businesses
Cash and bank Bank reconciliations, dual authorisation of payments, petty cash counts, access to online banking Reconciliations prepared late or not reviewed; one person able to create and approve a payment
Procure-to-pay Vendor onboarding and supplier verification records, purchase orders, three-way match, approval limits Vendors added without checks; invoices paid without a purchase order or goods receipt
Order-to-cash Credit approval, pricing and discounts, invoicing, collections, credit notes Discounts given outside policy; credit notes raised without approval
Inventory Stock counts, write-offs, goods received, slow-moving stock review Book stock differing from physical counts; write-offs not approved
Payroll and HR Joiner and leaver processing, salary changes, overtime approval, end-of-service calculations Leavers paid after exit; salary changes without documented approval
Fixed assets Asset register, tagging, disposals, capital approval Register not matching assets on site; disposals not recorded
IT and system access User rights in the accounting system or ERP, password rules, backups, audit trail Shared logins; finance staff able to post and approve their own entries

Vendor onboarding now carries a tax consequence as well as a fraud one. From 1 October 2026 the FTA expects documented supplier checks before input VAT is deducted, so a weak onboarding process can cost recoverable VAT as well as cash. We test both sides in the same review; the rules are set out in the tax-controls section below.

Where written procedures are missing or out of date, we map the actual process and recommend a practical control set that suits your headcount. Small finance teams cannot always separate every duty, so we suggest compensating controls such as owner review of the bank statement or monthly exception reports. If the underlying bookkeeping needs rebuilding first, our outsourced accounting team can do that under a separate engagement.

Tax, VAT and regulatory controls we check

Many control failures in UAE companies show up first as a tax problem: a missing invoice, a record that cannot be produced, an input VAT claim on a supplier nobody checked, or an error found too late. We add a tax-controls review to the plan so these are picked up internally, before an FTA audit.

Area The rule What we check
Corporate tax records Records must be kept for 7 years after the end of the tax period they relate to (Federal Decree-Law 47/2022, Art. 56) Retention policy, where records are stored, and whether older periods can actually be retrieved
VAT and tax procedures records Failure to keep required records carries a penalty of AED 10,000, or AED 20,000 for a repeat within 24 months of the last violation (Cabinet Decision 40/2017 as amended by Cabinet Decision 129/2025, in force since 14 April 2026) Completeness of the VAT audit trail from invoice to return
Tax invoices and credit notes Failure to issue a tax invoice or tax credit note within the legal period: AED 2,500 for each case detected (same decision) Sample of sales invoices and credit notes against VAT requirements
Supplier and supply verification From 1 October 2026, FTA Decision 13/2026 requires a business to verify a supplier’s identity, place of business and risk indicators before deducting input VAT, to review each supply’s price, payment terms and commercial logic, and to keep a documented policy naming who runs and supervises these checks. Suppliers are verified on first dealing and again if not verified in the previous 12 months Whether vendor onboarding captures the required evidence, whether re-verification is scheduled, and whether the written policy exists and is followed
Bank confirmation for larger suppliers Under the same decision, where supplies from one supplier exceed AED 375,000 over the previous 12 months (or are expected to over the next 12), a written confirmation from a UAE bank that the supplier holds an account is required. Supplies under AED 10,000 excluding VAT are exempt, unless that supplier’s total exceeds AED 100,000 over 12 months Which suppliers cross the thresholds and whether bank confirmations are on file
Cash payments and input VAT Cabinet Decision 149/2026 adds Article 54(3) to the VAT Executive Regulation from 1 October 2026: input VAT cannot be recovered on a supply above an amount set by Ministerial decision where it is paid, or intended to be paid, in cash How cash payments to suppliers are approved and recorded, so claims can be tested against the Ministerial limit when it applies
Correcting errors From 1 April 2026, a tax difference above AED 10,000 needs a voluntary disclosure within 20 business days; AED 10,000 or less can be corrected in the next return (Cabinet Decision 17/2026) Whether your team has a routine to spot, quantify and escalate errors in time
E-invoicing readiness Businesses with revenue of AED 50 million or more must appoint an Accredited Service Provider by 30 October 2026 and go live by 1 January 2027; those below AED 50 million by 31 March 2027 and 1 July 2027 (Ministerial Decision 244/2025 as amended by Ministerial Decision 66/2026) Master data quality, invoice approval flow and project ownership
Beneficial ownership Changes to the beneficial owner register must be recorded within 15 days of becoming aware of them (Cabinet Decision 109/2023, Art. 8) Whether the register matches the current shareholding and control

Controls also matter for the external audit. Under Ministerial Decision 84/2025, for tax periods starting on or after 1 January 2025, audited financial statements are required for corporate tax purposes where revenue exceeds AED 50 million, for every Qualifying Free Zone Person, and for every tax group. A business whose controls work tends to have a smoother year-end audit with fewer adjustments. For filing and advisory work, see our VAT services, corporate tax services and e-invoicing pages; if an error has already been found, our voluntary disclosure team can help.

Fraud-risk assessment

Most internal fraud in smaller companies relies on the same weaknesses: one person controlling a whole process, owners too busy to review, and nobody looking at the data. Our fraud-risk assessment looks at where opportunity exists and tests for signs that it has been used.

  • Workshop and interviews – we walk through each process with the people who run it and identify where someone could divert cash, goods or data without being noticed.
  • Data analytics – we run tests across the full ledger rather than a sample: duplicate invoice numbers and amounts, payments split to stay under approval limits, vendors sharing bank details or addresses with employees, round-sum and weekend journal entries, and payroll records with no matching employee file.
  • Control design review – segregation of duties, approval limits, vendor master changes, and who can edit bank details.
  • Anti-fraud measures – conflict-of-interest declarations, a channel for staff to raise concerns, and whether the delegation of authority is followed.

If testing turns up indicators of actual fraud, we report them promptly to the person named in the charter, normally the chair of the board or the owner, and advise on next steps such as preserving evidence and bringing in specialist investigators or legal counsel. Where money-laundering risk is part of the picture, our AML compliance service covers the regulatory side.

Manager in a suit reviewing a report at his desk while a colleague stands beside him

Reporting to the board, audit committee or owners

Internal audit only helps if findings lead to action. Each review ends with a draft report discussed with the process owner, then a final report to whoever the charter names: the board, an audit committee, or the owners in a family business.

Every report contains:

  • An executive summary with an overall rating for the area reviewed
  • Each finding with the condition found, the risk it creates, the root cause and a practical recommendation
  • Management’s response, the action owner and an agreed completion date
  • Appendices with the scope, sample sizes and tests performed
Rating Meaning Expected response
High A control is missing or failing, with a real risk of loss, misstatement, tax penalty or fraud Immediate action, reported to the board or owners
Medium A control exists but is inconsistent or poorly designed Fixed within an agreed timescale
Low An improvement to efficiency or documentation Addressed in the normal course of business

We keep an action tracker across all reviews and retest closed findings, so the board sees what has actually been fixed rather than what has been promised. Periodic summaries show open actions by age and risk rating, and any themes that repeat across departments.

Outsourced, co-sourced or in-house internal audit

There are three ways to set up the function. The right one depends on your size, how complex your operations are, and whether you already have internal audit staff.

Model Outsourced Co-sourced In-house team
Who does the work DirhamWise delivers the full plan Your internal auditor plus DirhamWise for set reviews or extra capacity Your own employees
Cost basis Fixed fee per review or per year Fixed fee for the reviews we cover Salaries, visas, training and benefits all year
Skills available A team covering finance, tax, payroll and IT controls Specialist skills added where your team has gaps Limited to the people hired
Independence from management External by design Strengthened by an external reviewer Depends on reporting line
Best suited to SMEs and family groups with no internal audit function Companies with one or two internal auditors Larger groups with continuous audit needs

Many companies start outsourced, move to co-sourcing once they hire a head of internal audit, and keep external support for specialist areas such as tax controls or IT access. If you also need wider finance leadership, our CFO services can sit alongside internal audit, though never on the same area we are auditing.

Independence, engagement steps and fees

Internal auditors must be free to report problems, including problems created by management. We keep that independence in three ways:

  • We do not audit work we have prepared. If DirhamWise keeps your books or runs your payroll, we leave those areas out of our internal audit scope and say so in the proposal.
  • We do not take management decisions. We recommend; your management decides and owns the fix.
  • We raise any conflict with your statutory audit arrangements before we start, so that the two roles stay separate.

A typical first engagement runs like this:

  1. Scoping call – we discuss your structure, systems, concerns and any recent issues raised by auditors or the FTA.
  2. Proposal – a written scope, the reviews planned, timing and a fixed fee.
  3. Planning – risk assessment, audit universe and charter, agreed with the board or owners.
  4. Fieldwork – walkthroughs, testing and data analytics, on site at your office or remotely with system access.
  5. Reporting – draft report, discussion with management, final report to the board or owners.
  6. Follow-up – retesting of agreed actions and an updated tracker.

Fees are fixed per engagement and depend on the number of entities, locations, processes in scope and how often you want reviews. Businesses usually start with either a one-off control review or a rolling annual plan. Contact us for an internal audit quote; our monthly accounting packages are listed separately on the pricing page. Our team is based at ParkLane Tower, Business Bay, and works Monday to Saturday, 9:00am to 6:00pm.

FAQ

Frequently asked questions

What is the purpose of internal audit?

Internal audit gives owners and the board an independent view of whether risks are managed, controls work and financial information is reliable. It finds weaknesses before they become losses, fraud, tax penalties or audit qualifications, and it tracks whether management fixes them.

Who does internal audit report to?

Functionally, internal audit should report to the board, an audit committee or, in owner-managed companies, the owners. Day-to-day administration can sit with the CEO or managing director, but the auditor must be able to raise findings directly with those charged with governance. The reporting line is set out in the internal audit charter.

What is an internal audit charter?

A charter is a short document approved by the board or owners that defines internal audit’s purpose, authority, scope, reporting lines, independence and access to people, records and systems. We draft it during planning so everyone knows what internal audit can see and whom it reports to.

How do you conduct an internal audit?

We assess risks, agree a plan, then for each area document the process, identify key controls, test a sample of transactions or the full data set, discuss findings with the process owner, issue a report with agreed actions, and retest once those actions are complete.

What is the difference between internal audit and external audit?

Internal audit reviews risks and controls for management and the board, with a scope they choose. External audit gives an independent opinion on the annual financial statements. Our internal vs external audit guide explains the difference in detail, and our audit and assurance page covers statutory audits.

How often should internal audits be performed?

High-risk areas such as cash, procurement and payroll are usually reviewed every year, and lower-risk areas every two or three years. The risk assessment sets the cycle, and it is reviewed when the business changes, for example after an acquisition, a system change or new tax rules.

Can our external auditor use the internal audit work?

International auditing standards allow external auditors to evaluate internal audit work and, where they judge it appropriate, take it into account in their own audit. The decision is theirs. Clear documentation, sound methodology and independence make that more likely.

TALK TO US

Get a fixed-fee internal audit quote

Tell us about your business, your systems and the areas that worry you. We will propose a risk-based scope and a fixed fee.

+971 56 500 6694 · info@dirhamwise.com · Contact form
ParkLane Tower, Park Regis, Business Bay, Dubai · Monday to Saturday, 9:00am to 6:00pm