Thank you
Our team of industry domain experts combined with our guaranteed SLAs, our world class technology .
Get Immediate Help
ADHICSUAE enterprises face supplier assurance duties under several regimes at once, including the PDPL, NESA, ADHICS, DESC, and free zone regulations. Tiering suppliers by risk makes a programme affordable, since assessing every vendor equally is unrealistic. This guide explains which regulations impose supplier duties, how to tier suppliers and match assessment depth, and how to build a programme that works.
Building the programme around these five points helps keep it proportionate and defensible.
The pressure comes from regulation as well as risk. Supplier assurance duties appear in federal personal data law, the national information assurance standard, the health standard in Abu Dhabi, Dubai's government regulation and the free zone regimes, and a single enterprise often sits under several. Our GRC overview explains how a governance function coordinates overlapping obligations.
This guide takes the UAE view and does not repeat the generic definition of third-party risk management, which global guides already cover. It focuses on which obligations apply, how to tier suppliers, what assessment each tier needs and how to run the programme in practice. A programme built around the regulations you actually face is easier to defend than a generic framework adopted whole, and our enterprise cyber risk management service shows how supplier risk connects to the wider risk picture.
| Regime | Supplier obligation | Applies to | What you must evidence |
| NESA / UAE IA | The standard's third-party security family governs supplier risk and the contractual security requirements placed on suppliers, service providers and outsourced or cloud-hosted services. | It applies to government entities and critical infrastructure operators, and suppliers inherit obligations through contract. | You must evidence supplier due diligence, security clauses in contracts, access boundaries and records of supplier activity. |
| ADHICS | The standard includes a third-party security domain covering policy, delivery and monitoring of third-party services, and technology and service providers follow a separate Service Provider control category. | It applies to Abu Dhabi health entities and, through the Service Provider category, the vendors that supply them. | You must evidence how you select, contract with and monitor third parties that handle health information. |
| Federal PDPL | A controller must appoint processors that give sufficient guarantees on security, and processors must act on instructions within a contract. | It applies to controllers and processors of personal data on the mainland and to entities abroad that process UAE residents' data. | You must evidence processor due diligence and a written agreement that defines scope, purpose and obligations. |
| DESC ISR | Obligations flow down to suppliers through contract, and cloud service providers need a separate DESC CSP Security Standard certification. | It applies to Dubai Government entities and, through contract, their suppliers and contractors. | You must evidence the controls the contract flows down and, for cloud providers, the CSP certification. |
| DIFC and ADGM | A controller must use a legally binding written agreement with each processor, and processors need the controller's prior authorisation before engaging a sub-processor. | They apply to entities licensed in the Dubai International Financial Centre and Abu Dhabi Global Market. | You must evidence processor agreements, sub-processor authorisations and the basis for choosing each processor. |
| Central Bank outsourcing rules | Banks must obtain a notice of no objection before outsourcing, keep ownership of the data they share and keep data needed for core activities in the UAE. | They apply to banks licensed by the Central Bank of the UAE. | You must evidence the no-objection notice, the outsourcing agreement terms and where the data is stored. |
When an entity falls under more than one regime, assess suppliers to the most demanding applicable standard and record the differences. A healthcare group with a free zone subsidiary can meet three of these at once, and one assessment standard applied across all suppliers avoids running parallel programmes.
Processor obligations under the federal law, including the conditions on cross-border transfers, are covered in our UAE PDPL compliance guide. That guide maps each obligation to the control that satisfies it.
The free zone regimes add their own processor and sub-processor rules, which our DIFC and ADGM data protection guide compares in detail. Firms in both zones should read it alongside this page.
Abu Dhabi health entities should read the supplier controls alongside the wider framework in our ADHICS compliance guide. Technology vendors serving them should check which control category applies to their own service.
The case most programmes get wrong is a supplier with low contract value and high data access, such as a small marketing platform holding customer lists or a boutique developer with administrator rights. Spend does not reveal risk, so score data access and connectivity independently of value. Document the scoring so you can explain a tier decision to an auditor and revisit it when the relationship changes. Our cyber risk assessment guide covers how to rate likelihood and impact consistently across a register.
| Tier | Assessment | Evidence required | Reassessment cadence |
| Tier 1, highest risk | A full assessment covers governance, technical controls, resilience and fourth parties, supported by direct review of evidence. | Independent certification or audit reports, penetration test summaries, continuity test results and contractual audit rights. | Review at least annually and after any major change or incident. |
| Tier 2, high risk | A structured assessment reviews the main control areas, and tests answers against evidence. | A completed questionnaire plus certifications or audit reports covering the service. | Review annually or every two years depending on risk. |
| Tier 3, moderate risk | A standard questionnaire and a check of public assurance, such as certifications, cover the basics. | A completed questionnaire and a copy of any relevant certification. | Review every two years or on a material change. |
| Tier 4, low risk | A light check at onboarding confirms the supplier holds no sensitive data and has no privileged access. | A short attestation and contract clauses covering basic security obligations. | Reassess only when scope changes or a trigger event occurs. |
Cadence by tier is a starting pattern and not a rule, so adjust it where a regulation or contract says otherwise. A trigger-based review, such as after a supplier breach, a change of ownership or a new data flow, should override the calendar at any tier. Reassessment findings should feed the same supplier risk register that drives tiering, so the register stays current.
A questionnaire cannot establish whether the described controls operate. Answers come from the supplier, often written by a sales or compliance team, and they describe intent as much as reality. Long questionnaires also invite copied answers and tick-box responses, and a high score can reflect good writing more than good security.
Several compliments raise confidence without multiplying effort. Certification evidence, such as ISO 27001 for a relevant scope, shows that an independent body has examined the management system, as our ISO 27001 certification guide explains. Independent audit reports, external attack surface reviews and penetration test summaries add evidence about how controls perform, and contractual audit rights let you test a claim if doubt arises.
Treat the questionnaire as the start of an assessment, not the end. Ask for evidence behind the answers that matter most for the tier, and follow up on any answer that conflicts with a certification or public information. Most suppliers answer honestly, so the goal is to verify the highest-risk areas and leave the rest to the questionnaire.
Visibility starts with the contract. DIFC and ADGM require processors to obtain the controller's prior authorisation before engaging a sub-processor, and the same approach works well as a baseline for any supplier handling sensitive data. Ask suppliers to list material subprocessors, notify you of changes and flow security obligations down to them.
Concentration risk compounds the problem. Several important suppliers may depend on the same underlying cloud provider or service, so one failure can disrupt many of them at once. A supplier-by-supplier register rarely shows that pattern, because each entry looks independent.
Mapping dependencies for the highest-tier suppliers is often enough to reveal the main concentrations. Where a concentration is material, express the exposure in financial terms so leadership can weigh mitigation, a topic our guide to cyber risk quantification covers. Mitigation can include alternative providers, exit plans or contractual resilience commitments.
A complete inventory usually takes longer than expected and is the step most programmes skip, which leaves the later steps built on a partial list. Realistic sequencing starts with the inventory and the procurement gate, since a gate stops the backlog growing while the assessments catch up. A vCISO can own the programme for organisations without a dedicated function, as our vCISO services guide explains.
A useful pack holds current certifications and their scope statements, recent independent audit or test summaries, policies, a completed standard questionnaire kept up to date and a description of subprocessors and data locations. Keep an owner for the pack, refresh it on a schedule and share it under confidentiality terms. Agree reasonable audit rights and breach notification terms once in a template, so each negotiation starts from a position you can accept.
Suppliers to government and infrastructure entities inherit obligations through the national standard, since its third-party family flows requirements down by contract, and our NESA compliance guide explains what that means for suppliers. Knowing which obligations a client carries helps you anticipate what they will ask of you.
Suppliers to Dubai Government entities meet the same pattern under the Dubai Information Security Regulation, and our DESC compliance guide covers how that framework applies to suppliers and cloud providers. Preparing before a tender is far easier than assembling evidence during one.
In parallel, fix the procurement gate so new suppliers arrive with a tier and an assessment, which stops the backlog growing while you work through it. Agree contractual clauses with legal early, since renegotiating existing contracts takes longer than writing a template for new ones. Our cyber risk management service describes how Microminder supports ongoing oversight once the programme is running.
A programme like this can help reduce supplier-related risk, though it cannot remove it, and results depend on how quickly teams act on what the assessments find. This article offers general guidance and does not constitute legal advice.
Don’t Let Cyber Attacks Ruin Your Business
Call
UK: +44 (0)20 3336 7200
KSA: +966 1351 81844
UAE: +971 454 01252
Contents
To keep up with innovation in IT & OT security, subscribe to our newsletter
Recent Posts
Cloud Security | 07/10/2026
Cloud Security | 07/10/2026
Cyber Threats | 07/10/2026
What is third-party risk management?
The process of identifying, assessing and monitoring risks that suppliers and other external parties create for your organisation.What is the difference between TPRM and supply chain risk management?
TPRM focuses on external parties with access to data or systems. Supply chain risk also covers goods, services and dependencies beyond them.Do UAE regulations require supplier security assessments?
Several do, including NESA, ADHICS and the PDPL for processors. See our NESA compliance guide.How often should we reassess suppliers?
Highest-risk suppliers usually annually, lower tiers less often, and any supplier after a breach, ownership change or new data flow.Is a security questionnaire enough assurance?
Rarely on its own. It shows documentation maturity, so add certifications, audit reports or testing for higher tiers.What is fourth-party risk?
Risk from your suppliers' own suppliers and subprocessors, which a supplier-by-supplier review does not capture.Does ADHICS cover third-party suppliers?
Yes. It has a third-party security domain and a Service Provider category for vendors. See our ADHICS compliance guide.How do we respond to a client security questionnaire?
Keep a standing evidence pack and a completed standard questionnaire. See our ISO 27001 certification guide.