Whistleblowing Policies in the UAE: Key Regulatory Requirements for Organizations

Whistleblowing Policies in the UAE: Key Regulatory Requirements for Organizations

There is no single federal standard for whistleblowing policy in the UAE, only a patchwork of regulators, each with their own requirements. Here's what ADGM, DFSA, CBUAE, and SCA actually require, and what it takes to meet those requirements in practice.

By the iVoiceUp Compliance Team

Whistleblowing policy requirements in the UAE vary by regulator, not by a single federal standard. Here  is what ADGM, DFSA, CBUAE, and SCA actually require, and what it takes to meet those requirements in  practice. 

There is no single federal law in the UAE that sets out whistleblower protection requirements for every  company. 

That surprises a lot of organizations, especially ones assuming a single national standard applies the way  it might elsewhere. What exists instead is a patchwork: several regulators, each with their own  whistleblowing requirements, applying to different types of entities depending on where and how they  operate. 

For any organization trying to figure out what applies to them, that patchwork is exactly the problem.  Here is what each regulator actually requires.


ADGM: Whistleblower Protection Regulations 2024

Copy of THE ORGANIZATION THAT CONFUSED LOYALTY WITH SILENCE (Instagram Post (45)) (1920 x 817 px) - 32 (2).png

ADGM published its Whistleblower Protection Regulations in July 2024, and by May 31, 2025, every  registered entity was expected to be compliant, with no transition period built in. It's one of the more  demanding frameworks in the region precisely because it doesn't treat any of this as optional. 

Covered entities have to do more than write a policy. They need to: 

● Maintain confidential and anonymous reporting channels people will actually use.

● Protect whistleblower identity throughout the process. 

● Retain disclosure records for a minimum of six years, long after most companies would assume  a case is closed. 

The bar is higher still for Designated Non-Financial Businesses and Professions, law firms and accounting  practices among them, and for what the regulations call Large Establishments: entities crossing USD 13.5  million in turnover or assets, or 35 employees. Once a business crosses that line, the classification stays  even if the company later shrinks below the threshold again. 

None of this is a paperwork exercise. The ADGM Registrar can issue censures, levy financial penalties, or go as far as suspending a commercial license altogether. 


DIFC and DFSA: A Regime in Practice, Not Just on Paper

Copy of THE ORGANIZATION THAT CONFUSED LOYALTY WITH SILENCE (Instagram Post (45)) (1920 x 817 px) - 33 (1).png

DFSA introduced its whistleblowing regime back in April 2022, and on paper, it reads like most  regulatory frameworks do: firms must maintain policies for internal reporting, escalate regulatory  concerns, protect whistleblower identity, and manage conflicts of interest through an investigation. 

What changed the conversation was what came next. In January 2025, DFSA published its  Whistleblowing Thematic Review, the product of a full year assessing regulated entities across eight  themes, from governance to training to record-keeping. 

The finding was direct: a policy on file isn't proof of anything. Firms need to demonstrate the framework  actually works when tested, and DFSA has made clear that future supervisory engagement will ask  exactly that question. 


CBUAE: Governance Obligation for Banks

Copy of THE ORGANIZATION THAT CONFUSED LOYALTY WITH SILENCE (Instagram Post (45)) (1920 x 817 px) - 34 (1).png

Under CBUAE's Corporate Governance Regulation for Banks, a bank's board is directly responsible for  establishing and communicating corporate culture through several required mechanisms, one of which  is a whistleblowing policy, alongside a written code of conduct and a conflict of interest policy. 

The accompanying Corporate Governance Standards spell out what that actually requires in practice:  staff must be able to raise legitimate concerns about illegal, unethical, or questionable practices confidentially, without fear of reprisal, and the board must approve who investigates those concerns,  whether that's an internal function, an external body, or the board itself. The board also carries direct  responsibility for protecting staff who raise concerns from retaliation. 

It's also worth drawing a clear line here, because the two can often get confused: CBUAE also runs its  own whistleblowing portal, but that exists for reporting concerns about the Central Bank itself, not  something CBUAE requires banks to build for their own employees. One is a regulatory obligation banks  carry internally. The other belongs to CBUAE alone. 


SCA: Governance Code for Listed Companies

Copy of THE ORGANIZATION THAT CONFUSED LOYALTY WITH SILENCE (Instagram Post (45)) (1920 x 817 px) - 35 (1).png

For public joint stock companies listed on the DFM or ADX, SCA’s Corporate Governance Code puts whistleblower reports on financial matters squarely in front of the audit committee, alongside oversight of anti-fraud and anti-corruption compliance. The committee is required to meet at least quarterly, and to meet separately with the external auditor at least twice a year, once before fieldwork, once to review findings.

Unlike ADGM or CBUAE, SCA’s Code doesn’t prescribe how the whistleblowing channel itself has to work, no stated confidentiality mechanism, no retention period. The requirement is about oversight: reports have to reach the audit committee and be acted on, but the operational design is left to the company.

SCA, like CBUAE, also maintains its own separate channel, open to employees, customers, suppliers, and partners who want to report conduct that runs against the authority’s own governance principles.


Employment Protection: Article 47 of the UAE Labour Law

Copy of THE ORGANIZATION THAT CONFUSED LOYALTY WITH SILENCE (Instagram Post (45)) (1920 x 817 px) - 36.png

Article 47 of Federal Decree-Law No. 33 of 2021 offers a narrower kind of protection, but a real one. It  makes it unlawful to terminate an employee over a serious, proven complaint filed with MOHRE, or a  valid lawsuit brought against the employer, with compensation capped at three months' wage. 

The key distinction is timing. Article 47 protects after the fact, once a complaint has already been filed  and proven true. It doesn't require a company to build any reporting infrastructure before that point,  which is exactly where it differs from ADGM and DFSA. 


What This Means in Practice

Copy of THE ORGANIZATION THAT CONFUSED LOYALTY WITH SILENCE (Instagram Post (45)) (1920 x 817 px) - 37.png

Across every one of these corporate governance and whistleblowing requirements, a pattern holds  regardless of which regulator applies: a policy has to translate into something that functions, not just  something that exists, and it has to hold up when a regulator asks to see how it works. 

That's the part a written policy alone can't deliver. ADGM's six-year record retention requirement and  CBUAE's confidentiality and no-reprisal mandate both assume a system built to protect identity and  produce records on demand. DFSA's expectation that firms demonstrate their framework functions asks  for the same thing in practice, not on paper. And SCA's audit committee, even without a prescribed  mechanism, still needs documented reports to actually review, something a policy document alone can't  provide. 


How iVoiceUp Helps You Meet These Requirements

Copy of THE ORGANIZATION THAT CONFUSED LOYALTY WITH SILENCE (Instagram Post (45)) (1920 x 817 px) - 38 (1).png

iVoiceUp provides the infrastructure a whistleblowing policy uae requirements actually depend on. Its  secure, anonymous reporting channel meets the confidentiality and identity-protection requirements  that ADGM, DFSA, and CBUAE specify directly, and gives SCA-regulated audit committees the  documentation they need for their own review process. 

Every report is timestamped and tracked through a structured case management workflow , generating  the documented investigation trail that DFSA's Thematic Review flagged as the real gap between having  a policy and having one that functions. That same record supports the retention window ADGM requires  and gives an audit committee, under SCA's Code, something concrete to review rather than a policy  summary. 

For organizations operating across multiple UAE regulatory frameworks at once, that infrastructure is what turns a written whistleblowing policy into something that holds up under the scrutiny each of  these regulators has made clear it intends to apply.

See how iVoiceUp helps you meet UAE whistleblowing requirements across every regulator. Talk to our team


Need a practical walkthrough for your team?

Book a demo and map your governance goals to the platform.