By the iVoiceUp Compliance Team
Whistleblowing policy requirements in the UAE vary by regulator, not by a single federal standard. Here is what ADGM, DFSA, CBUAE, and SCA actually require, and what it takes to meet those requirements in practice.
There is no single federal law in the UAE that sets out whistleblower protection requirements for every company.
That surprises a lot of organizations, especially ones assuming a single national standard applies the way it might elsewhere. What exists instead is a patchwork: several regulators, each with their own whistleblowing requirements, applying to different types of entities depending on where and how they operate.
For any organization trying to figure out what applies to them, that patchwork is exactly the problem. Here is what each regulator actually requires.
ADGM: Whistleblower Protection Regulations 2024
ADGM published its Whistleblower Protection Regulations in July 2024, and by May 31, 2025, every registered entity was expected to be compliant, with no transition period built in. It's one of the more demanding frameworks in the region precisely because it doesn't treat any of this as optional.
Covered entities have to do more than write a policy. They need to:
● Maintain confidential and anonymous reporting channels people will actually use.
● Protect whistleblower identity throughout the process.
● Retain disclosure records for a minimum of six years, long after most companies would assume a case is closed.
The bar is higher still for Designated Non-Financial Businesses and Professions, law firms and accounting practices among them, and for what the regulations call Large Establishments: entities crossing USD 13.5 million in turnover or assets, or 35 employees. Once a business crosses that line, the classification stays even if the company later shrinks below the threshold again.
None of this is a paperwork exercise. The ADGM Registrar can issue censures, levy financial penalties, or go as far as suspending a commercial license altogether.
DIFC and DFSA: A Regime in Practice, Not Just on Paper
DFSA introduced its whistleblowing regime back in April 2022, and on paper, it reads like most regulatory frameworks do: firms must maintain policies for internal reporting, escalate regulatory concerns, protect whistleblower identity, and manage conflicts of interest through an investigation.
What changed the conversation was what came next. In January 2025, DFSA published its Whistleblowing Thematic Review, the product of a full year assessing regulated entities across eight themes, from governance to training to record-keeping.
The finding was direct: a policy on file isn't proof of anything. Firms need to demonstrate the framework actually works when tested, and DFSA has made clear that future supervisory engagement will ask exactly that question.
CBUAE: Governance Obligation for Banks
Under CBUAE's Corporate Governance Regulation for Banks, a bank's board is directly responsible for establishing and communicating corporate culture through several required mechanisms, one of which is a whistleblowing policy, alongside a written code of conduct and a conflict of interest policy.
The accompanying Corporate Governance Standards spell out what that actually requires in practice: staff must be able to raise legitimate concerns about illegal, unethical, or questionable practices confidentially, without fear of reprisal, and the board must approve who investigates those concerns, whether that's an internal function, an external body, or the board itself. The board also carries direct responsibility for protecting staff who raise concerns from retaliation.
It's also worth drawing a clear line here, because the two can often get confused: CBUAE also runs its own whistleblowing portal, but that exists for reporting concerns about the Central Bank itself, not something CBUAE requires banks to build for their own employees. One is a regulatory obligation banks carry internally. The other belongs to CBUAE alone.
SCA: Governance Code for Listed Companies
For public joint stock companies listed on the DFM or ADX, SCA’s Corporate Governance Code puts whistleblower reports on financial matters squarely in front of the audit committee, alongside oversight of anti-fraud and anti-corruption compliance. The committee is required to meet at least quarterly, and to meet separately with the external auditor at least twice a year, once before fieldwork, once to review findings.
Unlike ADGM or CBUAE, SCA’s Code doesn’t prescribe how the whistleblowing channel itself has to work, no stated confidentiality mechanism, no retention period. The requirement is about oversight: reports have to reach the audit committee and be acted on, but the operational design is left to the company.
SCA, like CBUAE, also maintains its own separate channel, open to employees, customers, suppliers, and partners who want to report conduct that runs against the authority’s own governance principles.
Employment Protection: Article 47 of the UAE Labour Law
Article 47 of Federal Decree-Law No. 33 of 2021 offers a narrower kind of protection, but a real one. It makes it unlawful to terminate an employee over a serious, proven complaint filed with MOHRE, or a valid lawsuit brought against the employer, with compensation capped at three months' wage.
The key distinction is timing. Article 47 protects after the fact, once a complaint has already been filed and proven true. It doesn't require a company to build any reporting infrastructure before that point, which is exactly where it differs from ADGM and DFSA.
What This Means in Practice
Across every one of these corporate governance and whistleblowing requirements, a pattern holds regardless of which regulator applies: a policy has to translate into something that functions, not just something that exists, and it has to hold up when a regulator asks to see how it works.
That's the part a written policy alone can't deliver. ADGM's six-year record retention requirement and CBUAE's confidentiality and no-reprisal mandate both assume a system built to protect identity and produce records on demand. DFSA's expectation that firms demonstrate their framework functions asks for the same thing in practice, not on paper. And SCA's audit committee, even without a prescribed mechanism, still needs documented reports to actually review, something a policy document alone can't provide.
How iVoiceUp Helps You Meet These Requirements
iVoiceUp provides the infrastructure a whistleblowing policy uae requirements actually depend on. Its secure, anonymous reporting channel meets the confidentiality and identity-protection requirements that ADGM, DFSA, and CBUAE specify directly, and gives SCA-regulated audit committees the documentation they need for their own review process.
Every report is timestamped and tracked through a structured case management workflow , generating the documented investigation trail that DFSA's Thematic Review flagged as the real gap between having a policy and having one that functions. That same record supports the retention window ADGM requires and gives an audit committee, under SCA's Code, something concrete to review rather than a policy summary.
For organizations operating across multiple UAE regulatory frameworks at once, that infrastructure is what turns a written whistleblowing policy into something that holds up under the scrutiny each of these regulators has made clear it intends to apply.
See how iVoiceUp helps you meet UAE whistleblowing requirements across every regulator. Talk to our team .
