UAE IA. CBUAE.
ADHICS. DIFC. One GRC Platform.

Governance, risk and compliance on one control library for government, banks, healthcare and free-zone firms. Hosted in the UAE, in your private cloud or on-premises.

Already in use with regulated organisations in the region · Live in weeks to months

Federal. Emirate. Free Zone. One View.

A bank in Dubai answers to the Central Bank of the UAE. A hospital group in Abu Dhabi answers to the Department of Health’s ADHICS standard. A fintech in the DIFC answers to its own data protection regime. A group operating across all three answers to every one of them.

A new Central Bank law, a new Capital Market Authority and a new federal AI and data authority have all arrived since 2025, so the rulebook is still moving. Most teams still reconcile it in spreadsheets. Keep your advisors; give them one platform to work from.

LockThreat maps your obligations once, tests your controls continuously, and gives your board one current view of risk across every emirate and free zone you operate in.

The Rulebook Is Being Rewritten.

Sep 2025
UAE IA Standard v2
The Cyber Security Council’s new baseline, now covering AI and cloud.
16 Sep 2025
New Central Bank Law
Banking, payments and insurance brought under one decree-law.
14 Jun 2026
AI & Data Authority
A new federal authority absorbs the UAE Data Office.
14 Sep 2026
CBUAE Operational Risk
New rules for all licensed financial institutions, with ICT at the core.
Jan 2027
CMA Transition Ends
The one-year window to align with the new capital market laws closes.

Built for the UAE’s Most Regulated Sectors

Federal & Emirate Government

UAE IA Standard v2, Dubai ISR and national cyber policies.

Banks, Finance & Payments

CBUAE operational risk, outsourcing and consumer protection rules.

Healthcare

ADHICS, DHA data-sharing policy and federal health-data law.

DIFC & ADGM Firms

Free-zone data protection, plus DFSA and FSRA cyber rules.

Energy & Critical Infrastructure

The national CIIP policy and the UAE IA Standard.

Listed Companies & VASPs

CMA governance and internal control rules; VARA rules for Dubai VASPs.

Spreadsheets and IT-Only Tools Leave agap
Regulators Will Find.

Legacy Enterprise
GRC
Compliance-First Tools
LockThreat
UAE Frameworks
Custom build
Limited UAE depth
UAE IA, CBUAE, ADHICS, DIFC
GRC Depth
Full G+R+C
Compliance only
Full G+R+C
Deployment
Complex to configure
Typically SaaS only
In-UAE SaaS, cloud, on-prem
Multi-Regulator Mapping
Consultant-heavy
IT controls only
Test once, map across regulators
Continuous Monitoring
Limited or none
IT & cyber only
Enterprise-wide
AI Governance
Separate add-on
Limited
Built-in, incl. agentic AI
Time to Value
12–18 months
Weeks, compliance only
Weeks to months
UAE Frameworks
Legacy Enterprise GRC
Custom build
Compliance-First Tools
Limited UAE depth
LockThreat
UAE IA, CBUAE, ADHICS, DIFC
GRC Depth
Legacy Enterprise GRC
Full G+R+C
Compliance-First Tools
Compliance only
LockThreat
Full G+R+C
Deployment
Legacy Enterprise GRC
Complex to configure
Compliance-First Tools
Typically SaaS only
LockThreat
In-UAE SaaS, cloud, on-prem
Multi-Regulator Mapping
Legacy Enterprise GRC
Consultant-heavy
Compliance-First Tools
IT controls only
LockThreat
Test once, map across regulators
Continuous Monitoring
Legacy Enterprise GRC
Limited or none
Compliance-First Tools
IT & cyber only
LockThreat
Enterprise-wide
AI Governance
Legacy Enterprise GRC
Separate add-on
Compliance-First Tools
Limited
LockThreat
Built-in, incl. agentic AI
Time to Value
Legacy Enterprise GRC
12–18 months
Compliance-First Tools
Weeks, compliance only
LockThreat
Weeks to months

Frameworks for the UAE

Mapped to one control library, so a control tested once serves every framework it supports. Tracking something not listed? Ask us.

Categories
No frameworks match your search.

Federal Cyber & Data

UAE Information Assurance Standard v2 (UAE Cyber Security Council)
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL)
Critical Information Infrastructure Protection (CIIP) Policy
National Cloud Security Policy
National Third Party Security Policy
Federal Decree-Law No. 34 of 2021 on Combating Rumours and Cybercrimes
Federal Law No. 2 of 2019 on the Use of ICT in Health Fields

Dubai & Abu Dhabi

Dubai Information Security Regulation (ISR)
DESC Cloud Service Provider Security Standard
Abu Dhabi Healthcare Information & Cyber Security Standard (ADHICS)
DHA Policy for Health Data and Information Sharing

Financial Services & Capital Markets

CBUAE Operational Risk Management Regulation
CBUAE Outsourcing Regulation for Banks
CBUAE Consumer Protection Regulation & Standards
CBUAE Retail Payment Services & Card Schemes Regulation
Federal Decree-Law No. 10 of 2025 on AML/CFT
CMA (formerly SCA) Joint Stock Companies Governance Guide
VARA Technology & Information Rulebook
PCI DSS
SWIFT Customer Security Programme

Free Zones (DIFC & ADGM)

DIFC Data Protection Law, 2020
DIFC Data Protection Regulation 10 (Autonomous Systems)
DFSA Cyber Risk Management Rules
ADGM Data Protection Regulations, 2021
ADGM FSRA Cyber Risk Management Framework

Global Standards

ISO 27001:2022
ISO 22301
ISO/IEC 27701
NIST CSF 2.0
COSO (Committee of Sponsoring Organizations)

AI Governance

UAE Charter for the Development & Use of AI
National Cyber Security Policy for Artificial Intelligence
CBUAE Guidance Note on Consumer Protection and Responsible Use of AI & ML
ISO/IEC 42001 (AI Management System)
NIST AI Risk Management Framework (NIST AI RMF)
The Risk Nobody’s Governing

Your teams are already using AI on customer and patient data. Regulators from the Central Bank to the DIFC now expect you to govern it. Do you know which AI tools and agents are breaching your controls?

AI Security & Governance Flow

Your Data. In the UAE.

Sector rules keep key data onshore: health data under federal health law, a bank’s master record of customer data under CBUAE rules, and payment data under the CBUAE’s retail payments regulation.

Choose how LockThreat runs: managed SaaS hosted in the UAE, your own private cloud, or on-premises in your data centre. The same full G+R+C depth, regardless of deployment.

SaaS
Managed by us. Hosted in the UAE.
Private Cloud
Your cloud. Your boundary.
On-Premises
Fully within your walls.

One Platform for the Whole Buying Committee

Blue shield icon with a white award ribbon symbol featuring a star in the center.Vertical flowchart with four outlined circles connected by dotted lines in dark blue, beige, and light blue colors.
CISO
  • One evidence trail for UAE IA audits, Dubai ISR checks, ADHICS assessments and CBUAE reviews.
  • Third-party and supplier risk tracked alongside your own controls.
Line drawing of a human head and upper torso facing forward with a large dark blue dot near the brain area and a smaller bright blue dot near the upper chest.
Chief Risk & Compliance Officer
  • Operational risk quantified in financial terms with FAIR modelling and Monte Carlo simulation.
  • Policies and gap analysis generated against the frameworks you answer to.
Line art icon with a stylized head and shoulders and three floating dots above representing communication or connection.
Data Protection Officer
  • Federal PDPL, DIFC and ADGM obligations mapped to controls in one register.
  • Visibility of AI tools handling personal data.
Two overlapping blue circles connected by a black diagonal line on a white background.
Chief Audit Executive
  • Continuous control testing instead of periodic sampling.
  • Board and committee reporting drawn from live data, not spreadsheets.
Outline of a person’s head and shoulders with a blue circle above representing the mind or focus.

Everything Enterprise GRC Should Have Been.

True GRC Depth

Most GRC tools deliver compliance, with governance and risk as an afterthought.

Here, governance comes first: the policies that move your organisation forward, the controls that contain risk across every department, and the compliance that follows naturally from both.

No spreadsheets. No disconnected tools. No point-in-time snapshots. One centralised, ongoing view of your risk and compliance posture.

GRC for Everyone

Your regulatory obligations don’t respect org charts or borders.

Every department, from finance, legal and HR to operations, cyber and IT, managed in one place, without the sprawl.

The jurisdictions you operate in, from Abu Dhabi, Dubai and Sharjah to the DIFC, ADGM and your offices across the GCC, managed in one place without adding more tools.

AI Governance & Security

Which AI tools are your employees using? Are they approved? Are they handling personal data they shouldn’t under UAE or free-zone data protection law?

And when AI agents act autonomously, accessing systems, making decisions, breaching controls, who’s watching? Now you are.

From shadow AI discovery and ISO/IEC 42001 alignment to real-time prompt protection and agentic control enforcement, reported directly into your GRC framework.

Risk Clarity

Every stakeholder needs a different view of the same risk reality, from one source of truth.

Express risk in financial terms your board and CFO can act on, using FAIR modelling and Monte Carlo simulation.

Detailed enough for the analyst, clear enough for the Chief Risk Officer and the CISO, compelling enough for the board.

Continuous Assurance

Compliance isn’t an annual exercise; it’s an ongoing operating requirement.

LockThreat validates that your controls are working, right now, across cloud infrastructure, cyber endpoints and enterprise applications.

Far less scrambling for evidence before a UAE IA audit, a CBUAE review or an ADHICS assessment.

Framework Convergence

Map the UAE IA Standard, CBUAE regulations, ADHICS, Dubai ISR and the DIFC and ADGM rules to ISO 27001, NIST and SOC 2, and to each other, eliminating redundant work.

Tie everything to your own policy library and control framework, so governance becomes a living system, not a compliance filing cabinet.

Fast Time to Value

Enterprise GRC depth without the 18-month implementation. Up and running in weeks to months, on the technology stack you already have.

Implemented and supported by our in-region team and partners.

Already running another GRC platform? Run LockThreat alongside it during transition, no rip-and-replace required.

What GRC Leaders Say

Compliance across multiple international standards used to be a serious resource drain. LockThreat unified everything into one platform and eliminated the spreadsheet chaos entirely. It’s been a game-changer for our team.

Director of Risk & Compliance
World’s Most Sustainable City

LockThreat gave our team a single pane of glass across every framework we manage. What used to take weeks of manual mapping now happens automatically. Our clients see faster results and our consultants can focus on higher-value work.

Managing Director
Big-4 Professional Services Firm

We evaluated a lot of GRC tools and nothing came close to LockThreat’s combination of breadth across governance, risk and compliance, combined with AI automation and ease of use. Our team was up and running quickly, and the cross-framework mapping alone saved us hundreds of hours.

VP of Security & Risk
CirrusLabs

The real-time evidence validation and risk dashboards gave our leadership team the visibility they needed without burdening our security team. LockThreat just works.

Head of GRC
Octave

LockThreat fits perfectly into an agile environment. Controls and policies evolve alongside our work. It’s not a static compliance checkbox, it’s a living system that keeps up with our pace.

VP of Security
Agile Trailblazers

Connects to Your Existing Stack

See LockThreat on Your UAE Frameworks

A focused 30-minute walkthrough, plus pricing for your deployment. No generic pitch, no obligation.

Tell us which regulators and frameworks you answer to (UAE IA, CBUAE, ADHICS, Dubai ISR, DIFC or ADGM) and how you need to deploy. We’ll tailor the session to your programme.

  1. A 30-minute walkthrough on your frameworks, following your priorities.
  2. Your deployment path: SaaS hosted in the UAE, private cloud or on-premises.
  3. Pricing for your scope, based on your entities, frameworks and deployment model.

Delivered by our in-region team and partners. Prefer email? info@lockthreat.com