BlogGRC
September 1, 2026

DIFC Regulation 10: AI system certification requirements orgs need to know

Written by
Fazila Malik
Product Marketing Manager
Reviewed by
No items found.

Accelerating security solutions for small businesses 

Tagore offers strategic services to small businesses. 

A partnership that can scale 

Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate.

Standing out from competitors

Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

DIFC Regulation 10 is a new governance requirement that applies to organizations using AI systems to process personal data in the Dubai International Financial Centre (DIFC).

Organizations using AI for high-risk commercial activities—including credit scoring, employee monitoring, automated hiring decisions, and certain health or sensitive data processing—might be subject to additional obligations, including system certification and new, ongoing governance requirements.

What is DIFC Regulation 10?

The DIFC Data Protection Regulations introduced Regulation 10 on September 1, 2023, supplementing the DIFC Data Protection Law No. 5 of 2020. It governs how personal data is processed through autonomous and semi-autonomous systems. Full enforcement began in January 2026.

The regulation assigns responsibilities to three primary roles involved in the use of AI systems:

  • Deployer: The role that directs or benefits from the operation of the system, similar to a data controller.
  • Operator: The role that runs or supervises the system on the Deployer's behalf, similar to a data processor.
  • Provider: The role that develops or commissions the AI system for sale.

The role an organization plays determines which obligations it must meet under Regulation 10, including certification, governance, documentation, and oversight requirements.

Key requirements for Regulation 10 

Requirements for Regulation 10 that warrant extra scrutiny include: 

  • Mandatory certification for high-risk commercial AI systems. Certification is system-specific, not entity-specific, and only a DIFC-accredited certification body can issue it. Entities can't deploy or operate an uncertified AI system commercially if it involves high-risk processing.
  • Autonomous Systems Officer (ASO). Deployers and Operators engaged in high-risk processing must appoint an ASO to provide independent oversight of their autonomous and semi-autonomous systems. The ASO helps assess risks, monitors processing activities, advises senior management, and supports ongoing compliance.
  • AI registers and plain-language notices. Deployers and Operators must maintain a register of their AI systems and be able to explain processing, backed by supporting evidence, to affected individuals in non-technical terms.
  • A right to challenge outcomes. Data Subjects can dispute an AI system's outcome by submitting a complaint under the Data Protection Law.
  • Documented reliance on recognized standards. Systems must reference the codes, certifications, or principles they rely on, such as OECD, UNESCO, NIST, or Dubai Digital Authority guidelines.

Who is affected by DIFC Regulation 10?

Organizations using autonomous or semi-autonomous Systems for High-Risk Processing Activities in the DIFC may be subject to Regulation 10’s certification and Autonomous Systems Officer (ASO) requirements.

Under the DIFC Data Protection Law, High-Risk Processing Activities meet one or more of four criteria:

  1. New or different technology or methods. The processing adopts new or different technologies or methods that materially increase risks to a Data Subject’s security or rights, or make it more difficult for the Data Subject to exercise their rights.

  1. Considerable amounts of Personal Data combined with high risk. Significant amounts of Personal Data—including employee and contractor data—is processed, and that processing is likely to present a high risk to Data Subjects. Reasons for high risk include the sensitivity of the data, or risks to its security, integrity or privacy. Volume alone does not satisfy this limb. There must also be a likely high risk.

  1. Automated evaluation and significant decisions. The processing involves systematic and extensive evaluation of individuals through automated processing, which includes profiling that results in decisions that produce legal effects concerning the individual.

  1. Material amounts of Special Category Personal Data. A material amount of Special Category Personal Data is processed. This includes health, biometric, racial- or ethnic-origin, religious-belief, political-opinion, criminal-record, trade-union-membership, or sex-life data.

If your organization acts as a Deployer, Operator, or Provider of a System used commercially in the DIFC for High-Risk Processing Activities, you should assess which Regulation 10 requirements apply based on your role and how the System is used. 

Regulation 10 vs. the EU AI Act vs. ISO 42001

Organizations already preparing for ISO/IEC 42001 or the EU AI Act will recognize many of the governance concepts in Regulation 10, including documented risk management, defined organizational responsibilities, and oversight of AI systems.

Dimension DIFC Regulation 10 EU AI Act ISO 42001
What it is A binding DIFC regulation supplementing the Data Protection Law, governing personal data processed through autonomous and semi-autonomous (AI) systems. A binding EU regulation establishing a risk-tiered framework for AI systems placed on the EU market or put into service. A voluntary, certifiable international standard for an organization's AI management system (AIMS)—not a law.
Scope AI systems that process personal data in the DIFC, with added requirements when processing is high-risk and commercial. Any AI system placed on the EU market or affecting people in the EU, tiered from minimal to unacceptable risk. Any organization that develops, provides, or uses AI systems, regardless of jurisdiction.
What gets certified or assessed The individual AI system gets certified. Certification is system-specific and a DIFC-accredited certification body issues it. High-risk AI systems undergo a conformity assessment (internal or via a notified body), leading to an EU declaration of conformity and CE marking. The organization's AI management system as a whole, not each individual model or system.
Defined roles Deployer (similar to a controller), Operator (similar to a processor), and Provider (builds or commissions the system for sale). Provider, Deployer, Importer, and Distributor—each with distinct obligations. Doesn't prescribe legal roles. Requires defined organizational roles and top management accountability within the AI Management System (AIMS).
Named governance role The Autonomous Systems Officer (ASO) required for Deployers and Operators doing high-risk processing. This can be the same person as the Data Protection Officer (DPO). No single mandated officer title, but requires a documented quality management system and human oversight measures. No mandated officer title. Requires assigned responsibilities and management commitment as part of the AIMS.
Core documentation AI registers, plain-language processing notices, and evidence supporting non-technical explanations to affected individuals. Technical documentation, a risk management system, automatic event logging, and EU database registration for high-risk systems. Documented AIMS policies, AI risk and impact assessments, and a statement of applicability.
Status as of mid-2026 Introduced September 2023. Full enforcement began January 2026, meaning it's active now. Phased rollout since August 2024, now including high-risk system requirements, conformity assessment, and registration. Published December 2023. Adoption is ongoing and voluntary, with no enforcement deadline.

For organizations that already have an AI governance program aligned with ISO/IEC 42001 or the NIST AI Risk Management Framework, Regulation 10 is less about starting from scratch and more about demonstrating governance for specific high-risk AI systems operating in the DIFC.

How to prepare for Regulation 10 certification

There are four primary steps organizations should take to prepare for Regulation 10 certification:

  • Inventory every AI system used commercially in the DIFC. Flag which ones touch high-risk processing before you scope certification work.
  • Appoint or designate an ASO. Do this before certification begins, not during the process.
  • Build your AI register and explainability documentation now. Certification bodies will expect this as evidence, not as a work-in-progress.
  • Map Regulation 10 against any ISO 42001 or NIST AI RMF work already underway. This avoids duplicating governance work you've already done.

How Vanta and Middle East Privacy help organizations prepare for Regulation 10

While organizations must complete Regulation 10 certification through a DIFC-accredited certification body, they can begin preparing long before a formal assessment.

Vanta helps organizations build and maintain their governance foundations by:

  • Centralizing AI governance activities in a single platform.
  • Maintaining an inventory of AI systems and documenting the risks associated with each system.
  • Automating evidence collection to reduce manual work and support ongoing compliance efforts.
  • Continuously monitoring controls so teams can identify and address issues as their AI environment evolves.
  • Aligning governance activities with established frameworks, including ISO/IEC 42001 and the NIST AI Risk Management Framework, which helps organizations build on existing compliance investments.

Working with Middle East Privacy

Middle East Privacy provides expert outsourced ASOs, who help organizations establish and maintain an AI governance program that complies with Regulation 10. Combining our ASOs’ specialist regulatory expertise with Vanta’s continuous monitoring, evidence collection, and governance capabilities enables organizations to manage AI risks, maintain the required documentation, and demonstrate ongoing compliance. As a DIFC-accredited certification body, Middle East Privacy brings a practical, authoritative understanding of Regulation 10 and the standards organizations must meet to comply with it.

Together, Vanta and Middle East Privacy help organizations combine continuous AI governance with local regulatory expertise as they prepare for Regulation 10 certification.

If your organization is preparing for Regulation 10, learn how Vanta can help centralize AI governance, automate evidence collection, and support your certification readiness. Schedule a demo with Vanta.

A note from Vanta: Vanta is not a law firm, and this article does not constitute or contain legal advice or create an attorney-client relationship. When determining your obligations and compliance with respect to relevant laws and regulations, you should consult a licensed attorney.

Access Review Stage Content / Functionality
Across all stages
  • Easily create and save a new access review at a point in time
  • View detailed audit evidence of historical access reviews
Setup access review procedures
  • Define a global access review procedure that stakeholders can follow, ensuring consistency and mitigation of human error in reviews
  • Set your access review frequency (monthly, quarterly, etc.) and working period/deadlines
Consolidate account access data from systems
  • Integrate systems using dozens of pre-built integrations, or “connectors”. System account and HRIS data is pulled into Vanta.
  • Upcoming integrations include Zoom and Intercom (account access), and Personio (HRIS)
  • Upload access files from non-integrated systems
  • View and select systems in-scope for the review
Review, approve, and deny user access
  • Select the appropriate systems reviewer and due date
  • Get automatic notifications and reminders to systems reviewer of deadlines
  • Automatic flagging of “risky” employee accounts that have been terminated or switched departments
  • Intuitive interface to see all accounts with access, account accept/deny buttons, and notes section
  • Track progress of individual systems access reviews and see accounts that need to be removed or have access modified
  • Bulk sort, filter, and alter accounts based on account roles and employee title
Assign remediation tasks to system owners
  • Built-in remediation workflow for reviewers to request access changes and for admin to view and manage requests
  • Optional task tracker integration to create tickets for any access changes and provide visibility to the status of tickets and remediation
Verify changes to access
  • Focused view of accounts flagged for access changes for easy tracking and management
  • Automated evidence of remediation completion displayed for integrated systems
  • Manual evidence of remediation can be uploaded for non-integrated systems
Report and re-evaluate results
  • Auditor can log into Vanta to see history of all completed access reviews
  • Internals can see status of reviews in progress and also historical review detail
FEATURED VANTA RESOURCE

The ultimate guide to scaling your compliance program

Learn how to scale, manage, and optimize alongside your business goals.