By Marina Ivashina, Head of Compliance at TechnoPeak
Sooner or later, almost every financial firm in the UAE opens an email that contains some version of this sentence: “Please complete the attached cyber security questionnaire and return it within 10 business days.”
It might come from the DFSA or the FSRA. From a banking partner during onboarding. From an investor running due diligence. Or from a prospective client whose procurement team simply won’t sign anything without it.
The attachment might hold 30 questions. It might hold 300. Either way, most firms discover the same uncomfortable truth within the first hour: answering a cyber security questionnaire honestly is much harder than it looks. Question three asks when your Incident Response Plan was last tested, and the room goes quiet.
The good news? Preparing for these questionnaires is a very learnable skill. Having helped firms in the DIFC and ADGM through quite a few of them, I can tell you exactly what the requesting party is looking for — and how to be ready before the email arrives.
Nobody sends a 300-question spreadsheet out of spite (although at question 247 you may start to wonder). The purpose is genuinely practical. Whoever sent it wants to understand four things:
For banks and investors, the questionnaire is part of due diligence or onboarding. For clients, it is vendor assessment. For regulators such as the DFSA and FSRA, it feeds into thematic reviews and supervision — and as we covered in our article on what DIFC and ADGM regulators actually require for cyber resilience, those expectations have become considerably more specific in recent years.
The format varies, but the substance rarely does. Almost every cyber security questionnaire circles the same six areas.
Expect questions like: Who is responsible for cyber security? How often are risks reviewed? Does senior management receive reporting?
The sender is checking whether cyber security has an owner and oversight — or whether it lives in the vague territory of “our IT guy handles that.” (He may well be excellent. But “the IT guy handles it” is not a governance framework, and assessors can smell the difference through a spreadsheet.)
You will be asked about your Information Security Policy, Incident Response Plan, Access Control Policy, and your business continuity and disaster recovery plans (BCP and DRP).
Most firms happily tick “Yes” to all of these. The real test comes one step later, when the assessor asks to see them — with a recent review date, a named owner, and some sign that anyone has read them since they were written.
Is multi-factor authentication (MFA) enabled everywhere? Are privileged accounts controlled? Are user access rights reviewed regularly, and can you show the review?
This section gets extra scrutiny for a simple reason: a large share of real incidents begin with one compromised account. If your answer to “are access reviews performed?” is “we did one when Ahmed left,” it’s worth fixing that before the questionnaire arrives, not after.
How are incidents reported? Who leads the response? Have you run an exercise?
Firms that have tested their incident response — even a modest tabletop exercise once a year — answer these questions in five confident minutes. Firms that haven’t tend to produce answers that sound aspirational rather than factual. Assessors notice.
Do you have a BCP and DRP? Are they tested? When was the last test, and what did it find?
This is usually where evidence becomes the sticking point. A continuity plan that has never been tested is a hypothesis, not a plan. If you want a refresher on what good looks like, we’ve written a practical guide to disaster recovery essentials.
Modern financial firms run on cloud platforms, SaaS tools and managed IT providers. Questionnaires increasingly ask how you oversee those vendors: due diligence before signing, security clauses in contracts, and periodic reviews afterwards.
The irony of receiving a vendor assessment questionnaire and realising you’ve never sent one to your own vendors is not lost on anyone. Consider it a nudge.
After enough questionnaires, the failure patterns become predictable:
The single most useful habit is maintaining a small compliance evidence library — one organised folder that holds:
None of this requires a big team or an enterprise GRC platform. It requires an owner, a folder structure, and an hour or two a month. When the questionnaire lands, you’re assembling answers from evidence you already have — instead of reconstructing history under a deadline.
Here is the part that surprises people: nobody expects perfection. In years of working with regulated firms, I have never seen an assessor reject a company for honestly saying “this control is partially implemented, and here is our plan to complete it.”
What they want to see is:
A firm with modest but real controls and honest documentation will outperform a firm with a beautiful 80-page policy suite that nobody has opened since it was written. Assessors read impressive-but-untouched policies the way teachers read essays written the night before. They always know.
TechnoPeak works with DIFC- and ADGM-based firms on exactly this: preparing for regulatory reviews, cyber security questionnaires, investor due diligence and vendor assessments, and building the compliance evidence library that makes all of them easier. It’s one of the reasons FSRA-regulated firms in Abu Dhabi work with us, alongside our broader cybersecurity services and managed security services.
If you’re not sure whether your current documentation would stand up to scrutiny, a focused Cyber & Compliance Readiness Assessment is a practical place to start. We’ll tell you honestly where you stand — ideally before someone with a 300-row spreadsheet does.
Marina Ivashina is Head of Compliance at TechnoPeak, where she helps UAE financial firms turn regulatory requirements into working practice.
Let’s talk about how businesses can turn challenges into opportunities
A quick guide to staying safe from phone scams in the UAE.
Cybersecurity is no longer something a regulated firm can politely leave with the IT team and hope for the best. For FSRA-regulated firms, cyber risk is not just an operational issue. It belongs to governance, accountability, operational resilience, and evidence. In plain terms, an IT admin, an outsourced provider, Microsoft 365, backups, and a few […]
Contact us now – our team is ready to assist you!