“A critical gap is emerging – one that extends well beyond banking and applies to any institution regulated by the Central Bank of the UAE (CBUAE), including insurance providers, fintechs, payments businesses and other financial institutions,” Renan Ozturk, a Partner at Gateley Middle East, told Arabian Business.
“At its core, the issue is simple. Compliance with the Ministry of Finance (MoF) eInvoicing framework does not equate to compliance with CBUAE regulation.”
Why it’s important to meet the requirements
Ozturk said organisations need to understand that this the e-invoicing mandate is a tax framework, and not a financial regulatory one.
“The UAE’s e-invoicing model is built around MoF/FTA accreditation of ASPs. This framework broadly ensures that providers can generate and transmit structured invoice data, meet reporting and audit requirements, and maintain compliant records,” he said.
“However, the issue that arises stems from the fact that entities regulated by the CBUAE operate under an entirely different, and significantly broader, set of obligations.”
Some of the differences in obligations include data sovereignty and localisation requirements, customer confidentiality and protection standards, outsourcing and operational risk rules, cross-border data transfer restrictions under the PDPL and AML and financial crime considerations.
“These obligations are not assessed as part of ASP accreditation, and the result of that is a growing disconnect. Businesses are implementing solutions that are tax-compliant, but not necessarily aligned with the regulatory frameworks that actually govern their operations,” said Ozturk.
DIFC Dubai: Image / Shutterstock
The data sovereignty trap
According to Ozturk, who is also the Head of Tax at Gateley Middle East, the most visible area of misunderstanding lies in how “data sovereignty” is interpreted.
“Many ASPs highlight that invoice data is stored within the UAE. Under the MoF framework, this may be sufficient. However, under CBUAE expectations, it is often inadequate, as for regulated entities, sovereignty is not limited to storage. It extends to processing, control, replication, and access,” he said.
Crucially, even partial or temporary movement of data outside the UAE can trigger regulatory concerns.
Ozturk highlighted how this distinction is not widely understood and is already leading to structural weaknesses in implementation design.
How this plays out in practice
Across live projects, several recurring design patterns are emerging.
Each may meet MoF requirements but create potential exposure under a CBUAE lens.
“Cloud environments commonly replicate data across regions. Under CBUAE interpretation, a backup stored abroad may be treated as a primary record leaving the country – regardless of where the original data resides. Data may be hosted in the UAE but processed abroad – for tax engines, analytics, or fraud detection. Even transient processing can constitute a cross-border transfer,” said Ozturk.
Ozturk also shed a light on the issue of ‘outside control’.
“Even where hosting is local, control may sit with foreign entities – raising exposure to extraterritorial legal regimes and third-country access risk. Encryption is often cited as mitigation. However, if encryption keys are controlled offshore, sovereignty concerns remain,” he said.
Ozturk added: “Individually, these issues may appear technical. Collectively, they highlight a more fundamental point and that is the fact many organisations are outsourcing regulated data processing into environments that do not meet the full spectrum of their regulatory obligations.”
Abu Dhabi Skyline: Image / Shutterstock
The outsourcing reality
A second, and equally important, misconception relates to the nature of ASPs themselves.
There is a tendency to treat e-invoicing as an extension of existing internal systems or vendor relationships. This is misleading.
“The distinction is clear. Internal systems (e.g. ERP or tax engines) operate within the organisation’s controlled environment. ASPs – for e-invoicing specifically – operate externally, processing and transmitting data outside the entity’s direct control,” Ozturk said.
“That boundary transforms the arrangement into a regulated outsourcing relationship. For CBUAE-regulated entities, this triggers requirements around vendor due diligence, data governance and control, risk management and oversight and regulatory accountability.”
Why this matters now
The timing of this issue is critical.
Organisations across the UAE are making foundational decisions – selecting providers, designing architectures, and embedding operating models.
As Ozturk outlined, the implications of those decisions will be long-lasting.
“Once an ASP model is implemented, addressing gaps in data flow, control, or jurisdictional exposure becomes significantly more complex. What could have been addressed through design must instead be resolved through remediation. And in a regulatory environment where both tax authorities and financial regulators are increasing oversight, that is not a comfortable position to be in,” said Ozturk.
Reframing the question
Ozturk stressed thar for CBUAE-regulated entities, e-invoicing should not be viewed as a compliance exercise led by tax or IT teams alone.
It is a cross-regulatory issue that requires alignment between tax, technology, risk and compliance, legal and data governance.
“I believe that ASP selection should be reframed. This is not simply a question of whether a provider is accredited. It is a question of whether the operating model maintains full control over regulated data, avoids unintended cross-border exposure, meets outsourcing and operational risk expectations, and aligns with both tax and financial regulatory frameworks,” said Ozturk.
A narrow window to get it right
The UAE’s move toward e-invoicing represents a significant step forward in digital tax administration.
But for regulated entities, it also exposes a deeper challenge: navigating overlapping regulatory regimes that were not designed with each other in mind.
“The risk is not failing to comply with MoF requirements. It is assuming that doing so is enough. Organisations that recognise this distinction now – and adjust their approach accordingly – will avoid costly redesigns and regulatory friction later. Those that do not may find themselves in a familiar but uncomfortable position, which is compliant in form but exposed in substance,” said Ozturk.


