Share this article

DIFC Regulation 10: AI system certification requirements orgs need to know
Accelerating security solutions for small businesses Tagore offers strategic services to small businesses. | A partnership that can scale Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. | Standing out from competitors Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market. |
DIFC Regulation 10 is a new governance requirement that applies to organizations using AI systems to process personal data in the Dubai International Financial Centre (DIFC).
Organizations using AI for high-risk commercial activities—including credit scoring, employee monitoring, automated hiring decisions, and certain health or sensitive data processing—might be subject to additional obligations, including system certification and new, ongoing governance requirements.
What is DIFC Regulation 10?
The DIFC Data Protection Regulations introduced Regulation 10 on September 1, 2023, supplementing the DIFC Data Protection Law No. 5 of 2020. It governs how personal data is processed through autonomous and semi-autonomous systems. Full enforcement began in January 2026.
The regulation assigns responsibilities to three primary roles involved in the use of AI systems:
- Deployer: The role that directs or benefits from the operation of the system, similar to a data controller.
- Operator: The role that runs or supervises the system on the Deployer's behalf, similar to a data processor.
- Provider: The role that develops or commissions the AI system for sale.
The role an organization plays determines which obligations it must meet under Regulation 10, including certification, governance, documentation, and oversight requirements.
Key requirements for Regulation 10
Requirements for Regulation 10 that warrant extra scrutiny include:
- Mandatory certification for high-risk commercial AI systems. Certification is system-specific, not entity-specific, and only a DIFC-accredited certification body can issue it. Entities can't deploy or operate an uncertified AI system commercially if it involves high-risk processing.
- Autonomous Systems Officer (ASO). Deployers and Operators engaged in high-risk processing must appoint an ASO to provide independent oversight of their autonomous and semi-autonomous systems. The ASO helps assess risks, monitors processing activities, advises senior management, and supports ongoing compliance.
- AI registers and plain-language notices. Deployers and Operators must maintain a register of their AI systems and be able to explain processing, backed by supporting evidence, to affected individuals in non-technical terms.
- A right to challenge outcomes. Data Subjects can dispute an AI system's outcome by submitting a complaint under the Data Protection Law.
- Documented reliance on recognized standards. Systems must reference the codes, certifications, or principles they rely on, such as OECD, UNESCO, NIST, or Dubai Digital Authority guidelines.
Who is affected by DIFC Regulation 10?
Organizations using autonomous or semi-autonomous Systems for High-Risk Processing Activities in the DIFC may be subject to Regulation 10’s certification and Autonomous Systems Officer (ASO) requirements.
Under the DIFC Data Protection Law, High-Risk Processing Activities meet one or more of four criteria:
- New or different technology or methods. The processing adopts new or different technologies or methods that materially increase risks to a Data Subject’s security or rights, or make it more difficult for the Data Subject to exercise their rights.
- Considerable amounts of Personal Data combined with high risk. Significant amounts of Personal Data—including employee and contractor data—is processed, and that processing is likely to present a high risk to Data Subjects. Reasons for high risk include the sensitivity of the data, or risks to its security, integrity or privacy. Volume alone does not satisfy this limb. There must also be a likely high risk.
- Automated evaluation and significant decisions. The processing involves systematic and extensive evaluation of individuals through automated processing, which includes profiling that results in decisions that produce legal effects concerning the individual.
- Material amounts of Special Category Personal Data. A material amount of Special Category Personal Data is processed. This includes health, biometric, racial- or ethnic-origin, religious-belief, political-opinion, criminal-record, trade-union-membership, or sex-life data.
If your organization acts as a Deployer, Operator, or Provider of a System used commercially in the DIFC for High-Risk Processing Activities, you should assess which Regulation 10 requirements apply based on your role and how the System is used.
Regulation 10 vs. the EU AI Act vs. ISO 42001
Organizations already preparing for ISO/IEC 42001 or the EU AI Act will recognize many of the governance concepts in Regulation 10, including documented risk management, defined organizational responsibilities, and oversight of AI systems.
For organizations that already have an AI governance program aligned with ISO/IEC 42001 or the NIST AI Risk Management Framework, Regulation 10 is less about starting from scratch and more about demonstrating governance for specific high-risk AI systems operating in the DIFC.
How to prepare for Regulation 10 certification
There are four primary steps organizations should take to prepare for Regulation 10 certification:
- Inventory every AI system used commercially in the DIFC. Flag which ones touch high-risk processing before you scope certification work.
- Appoint or designate an ASO. Do this before certification begins, not during the process.
- Build your AI register and explainability documentation now. Certification bodies will expect this as evidence, not as a work-in-progress.
- Map Regulation 10 against any ISO 42001 or NIST AI RMF work already underway. This avoids duplicating governance work you've already done.
How Vanta and Middle East Privacy help organizations prepare for Regulation 10
While organizations must complete Regulation 10 certification through a DIFC-accredited certification body, they can begin preparing long before a formal assessment.
Vanta helps organizations build and maintain their governance foundations by:
- Centralizing AI governance activities in a single platform.
- Maintaining an inventory of AI systems and documenting the risks associated with each system.
- Automating evidence collection to reduce manual work and support ongoing compliance efforts.
- Continuously monitoring controls so teams can identify and address issues as their AI environment evolves.
- Aligning governance activities with established frameworks, including ISO/IEC 42001 and the NIST AI Risk Management Framework, which helps organizations build on existing compliance investments.
Working with Middle East Privacy
Middle East Privacy provides expert outsourced ASOs, who help organizations establish and maintain an AI governance program that complies with Regulation 10. Combining our ASOs’ specialist regulatory expertise with Vanta’s continuous monitoring, evidence collection, and governance capabilities enables organizations to manage AI risks, maintain the required documentation, and demonstrate ongoing compliance. As a DIFC-accredited certification body, Middle East Privacy brings a practical, authoritative understanding of Regulation 10 and the standards organizations must meet to comply with it.
Together, Vanta and Middle East Privacy help organizations combine continuous AI governance with local regulatory expertise as they prepare for Regulation 10 certification.
If your organization is preparing for Regulation 10, learn how Vanta can help centralize AI governance, automate evidence collection, and support your certification readiness. Schedule a demo with Vanta.
A note from Vanta: Vanta is not a law firm, and this article does not constitute or contain legal advice or create an attorney-client relationship. When determining your obligations and compliance with respect to relevant laws and regulations, you should consult a licensed attorney.





FEATURED VANTA RESOURCE
The ultimate guide to scaling your compliance program
Learn how to scale, manage, and optimize alongside your business goals.













.png)
.png)





.png)
.png)