Falconry Solutions · Present across the Emirates

Built for the UAE
— onshore and in the financial centres.

A GCC-native advisory and technology firm helping mainland institutions, DIFC and ADGM entities, sovereign investors and government-linked companies create value, protect trust and transform with confidence — across one of the world's most demanding regulatory landscapes.

Presence

Abu Dhabi

Advisory & delivery base

Reach

Onshore & free zones

Mainland · DIFC · ADGM

Team

Practitioner-led

Senior specialists, local presence

Mandate

"We the UAE" 2031

Trust, resilience & growth

A GCC Firm, Present in the Emirates

The UAE is our home market — not a visiting territory.

Falconry is GCC-native, based in the Emirates, and built for institutions operating under one of the most sophisticated regulatory environments in the region — spanning onshore federal supervision and the DIFC and ADGM financial free zones.

Present, not fly-in.

Based in Abu Dhabi and working across the Emirates — engaged for the long term and present between projects, not a team that arrives for a workshop and leaves.

Practitioner-led delivery.

Senior specialists who have built, run and audited these functions inside sovereign, regulated and government-linked institutions in the UAE — backed by the depth of a wider GCC advisory and technology firm.

Built for national ambition.

Our work is framed around the UAE's growth and trust agenda — diversification, a world-class financial sector, digital government and resilient critical services.

One Country, Three Regulatory Worlds

Onshore, DIFC and ADGM — we work fluently across all three.

The UAE's distinctive strength is also its complexity: federal onshore supervision alongside two common-law financial free zones, each with its own regulator, rulebook and data-protection regime. Institutions frequently span more than one. We help you operate across them as one coherent control environment.

Onshore / Mainland

Federal UAE

Federal supervision of banking, insurance and finance by the Central Bank of the UAE, and of securities and commodities by the Securities and Commodities Authority — under UAE federal law.

DIFC

Dubai International Financial Centre

A common-law financial free zone regulated by the Dubai Financial Services Authority, with its own rulebook and the DIFC Data Protection Law — including its AI provisions under Regulation 10.

ADGM

Abu Dhabi Global Market

A common-law financial free zone based on the laws of England and Wales, regulated by the Financial Services Regulatory Authority, with the ADGM Data Protection Regulations 2021 closely aligned to the GDPR.

The Full Proposition, Localised

Four practices, framed for the Emirates.

The same connected proposition we bring across the GCC — value creation and value protection — read through the lens of UAE institutions, regulators and national priorities.

Transform

Strategy, transformation & decision intelligence.

Corporate and portfolio strategy, operating-model design, digital and AI enablement, and transformation assurance for consequential change.

In the UAE: Supporting sovereign-investor and government-linked entity transformation, and AI adoption under the National AI Strategy 2031.

Govern

Governance, risk, compliance & assurance.

Board and committee design, ERM, compliance, internal audit and ICFR working as one operating model.

In the UAE: Aligned to CBUAE and CMA onshore, and to DFSA and FSRA rulebooks for DIFC- and ADGM-based entities.

Protect

Digital trust, cyber, privacy & resilience.

Cyber GRC, privacy operating models, technology risk, business continuity and operational resilience.

In the UAE: NESA IAS and NCEMA 7000 readiness, PDPL and free-zone data protection, and tested resilience for critical services.

Sustain

People, sustainability & long-term value.

Workforce and leadership capability, Emiratisation-aligned talent development, ESG governance and sustainability reporting.

In the UAE: Building national capability and long-term value in step with the UAE's growth, sustainability and Net Zero 2050 agenda.

How We Deliver in the UAE

One connected journey — from priority to sustained capability.

Each stage delivers a usable outcome and prepares the next. We shape the answer, embed it as a working system, sustain it as a managed service, and transfer ownership to your people — so capability stays in the institution.

Shape the answer

Assess & design

Diagnose the priority and design the target operating model — grounded in the right UAE jurisdiction and regulator.

Embed the model

Operationalise

Turn frameworks into live workflows, evidence, dashboards and automation through the platform and FalconryX.

Sustain performance

Operate & improve

Run the capability with you — capacity, cadence and virtual leadership that keep governance, risk and resilience live.

Build ownership

Transfer & sustain

Transfer knowledge to your teams — building national capability in step with Emiratisation, not dependency.

The UAE Regulatory Landscape

We speak the language of the UAE's regulators.

From federal supervision to the financial free zones and a maturing data-protection regime, UAE institutions face layered, increasingly enforced expectations. Our propositions are designed to help you meet them with evidence, not just intent.

Central Bank of the UAE

Banking · insurance · finance (onshore)

The federal supervisor of banks, insurers, finance companies and payment providers. The new Central Bank Law (Federal Decree-Law 6/2025) came into force in September 2025 with a one-year regularisation period, alongside standards for risk, outsourcing, cyber and enabling technologies.

How we help

Enterprise and operational risk, outsourcing and third-party risk, cyber governance and board-level risk reporting aligned to CBUAE expectations.

Capital Market Authority

Securities · commodities · markets (onshore)

The federal capital-markets regulator, established on 1 January 2026 by Federal Decree-Laws 32 and 33 of 2025 as the successor to the Securities and Commodities Authority (SCA) — with an expanded mandate over securities, commodities, funds and virtual assets, and strengthened supervisory and enforcement powers.

How we help

Governance, disclosure readiness, ICFR, internal audit quality and assurance for listed and CMA-licensed entities.

Financial Free-Zone Regulators

DIFC (DFSA) · ADGM (FSRA)

The independent regulators of the DIFC and ADGM financial free zones, each with its own common-law rulebook covering banking, asset management, securities, insurance and conduct — including growing AI and technology-governance expectations.

How we help

Cyber GRC, control mapping, evidence health, cloud assurance and incident-response readiness across regulated and government-linked entities.

Data Protection & Privacy

Federal PDPL · DIFC & ADGM regimes

The UAE's federal Personal Data Protection Law (Federal Decree-Law 45/2021), overseen by the UAE Data Office, sits alongside the DIFC Data Protection Law and the ADGM Data Protection Regulations 2021 — three regimes an institution may need to satisfy at once.

How we help

Privacy operating models, RoPA, DPIAs, DPO-as-a-service, cross-border transfer and breach response across federal, DIFC and ADGM regimes.

Where a proposition references CBUAE, CMA, DFSA, FSRA or PDPL alignment, it denotes capability designed to meet those expectations — not certification or endorsement by any UAE authority. Regulatory frameworks evolve; we track changes and map our propositions accordingly.

National Standards & Frameworks

The UAE-specific standards your teams are measured against.

Beyond the financial regulators, UAE institutions — especially critical-service and government-linked entities — are held to national standards for cyber and business continuity. Most large organisations must satisfy two or more at once. We help you meet them as one connected control environment, not a stack of separate audits.

NESA IAS (v2)

Information Assurance Standards

The UAE's federal cyber baseline — 188 controls across governance, operations and technology. Issued by NESA, now operating under the Signals Intelligence Agency (SIA), with national strategy set by the UAE Cybersecurity Council. Mandatory for government and critical infrastructure.

AE/SCNS/NCEMA 7000

National BCM Standard

The UAE's national business continuity standard (2021), developed by NCEMA — the National Emergency Crisis and Disaster Management Authority — and aligned with ISO 22301. Applicable to all UAE entities delivering essential operations.

DESC · ADHICS · TRM

Sector & Emirate Standards

Emirate- and sector-specific regimes — Dubai's DESC Information Security Regulation (ISR), Abu Dhabi's ADHICS for healthcare, and the DFSA and FSRA technology-risk rules for the free zones — that layer onto the federal baseline.

We help institutions map overlapping obligations — NESA IAS, NCEMA 7000, PDPL and sector regimes — to a single set of controls and evidence, reducing duplicated effort across audits and regulators.

What Each Leader Gets

Built for the leaders inside UAE institutions.

Every seat gets a flagship engagement — delivered as consulting and sustained through managed services and automation — mapped to the regulator and the jurisdiction that leader answers to in the UAE.

Board & Audit Committee

Governance
Flagship

Governance effectiveness, assurance mapping and board reporting across onshore and free-zone entities.

Managed & automated

A live board-reporting pack and assurance dashboard, refreshed each cycle.

CEO & Strategy

Value Creation
Flagship

Strategy & enterprise-risk operating model; transformation assurance for major programmes.

Managed & automated

Live strategy-to-risk dashboard with automated performance and risk signals.

CFO & Chief Audit

Assurance
Flagship

ICFR, controls and internal-audit quality for listed, CMA-, DFSA- and FSRA-regulated entities.

Managed & automated

Managed IA support and ICFR office; automated control testing and evidence health.

CRO & Compliance

Value Protection
Flagship

ERM, appetite and multi-regulator readiness across CBUAE, CMA, DFSA and FSRA.

Managed & automated

Managed GRC Office; automated obligation-to-control mapping across systems.

CISO & DPO

Digital Trust
Flagship

Cyber GRC cockpit aligned to NESA IAS, with a privacy operating model across PDPL, DIFC and ADGM regimes.

Managed & automated

Managed Cyber GRC with vCISO/vDPO; automated evidence, breach workflows and control health.

Resilience & Continuity

Value Protection
Flagship

Operational resilience and BCM aligned to NCEMA 7000, with crisis readiness for critical services.

Managed & automated

Managed resilience: BIA refresh, plan maintenance and exercise cadence.

The UAE Growth & Trust Agenda

Advisory that builds national capability, not just the project.

The UAE's ambitions — a diversified, knowledge-led economy, a world-class financial sector, digital government and net-zero commitments — depend on trusted, resilient institutions and capable national talent. Our model is built to leave capability behind, transferring ownership to UAE teams rather than creating dependency.

Economic diversification

Governance and risk foundations for non-oil growth and investment.

A world-class financial sector

Assurance and controls across onshore and free-zone regulators.

National capability

Emiratisation-aligned talent development and knowledge transfer.

Resilient, digital institutions

Cyber, continuity and AI governance for critical services.

Where We Work in the UAE

The institutions we serve across the Emirates.

Sovereign & Government-Linked

Sovereign investors, government entities and portfolio companies delivering national transformation agendas.

Banking & Financial Services

Onshore, DIFC and ADGM banks, insurers, asset managers and licensed institutions under CBUAE, CMA, DFSA and FSRA.

Energy, Utilities & Telecom

Critical-service organisations managing cyber, resilience, continuity and regulatory exposure across national infrastructure.

Corporates & Family Groups

Listed companies and diversified groups strengthening governance, controls, assurance and long-term value.

Why Falconry in the UAE

Local presence. Multi-jurisdiction fluency. Practitioner judgement.

Present in the Emirates

Based in the UAE, accountable locally and engaged for the long term — not a visiting advisory team.

All Three Jurisdictions

Fluent across onshore, DIFC and ADGM — helping institutions that span more than one operate as one control environment.

Consulting + Technology

Advice that becomes live workflows, evidence and decision intelligence — and can be run for you as a managed service.

Capability That Stays

Knowledge transfer to your teams in step with Emiratisation — we build ownership, not dependency.

Start with the UAE priority that cannot wait.

PDPL readiness, CBUAE or free-zone expectations, resilience for critical services, or a major transformation — we start focused, deliver locally, and build capability that lasts.